Vulnerability Report: GO-2023-1766
- CVE-2023-25568, GHSA-m974-xj4j-7qv5, and 1 more
- Affects: github.com/ipfs/go-libipfs, github.com/ipfs/go-bitswap
- Published: Jun 14, 2023
- Modified: May 20, 2024
An attacker can cause a Bitswap server to allocate and leak unbounded amounts of memory.
For detailed information about this vulnerability, visit https://github.com/ipfs/go-libipfs/security/advisories/GHSA-m974-xj4j-7qv5.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.4.1, from v0.5.0 before v0.6.0all symbols
-
before v0.12.0all symbols
Aliases
References
- https://github.com/ipfs/go-libipfs/security/advisories/GHSA-m974-xj4j-7qv5
- https://vuln.go.dev/ID/GO-2023-1766.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.