The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade golang-testsUpgrade golangUpgrade golang-miscUpgrade golang-binUpgrade golang-srcUpgrade golang-docs | Aug 28, 2019 | Oct 5, 2017 |
| Debian | — | Upgrade golang-1.7Upgrade golangUpgrade golang-1.8 | Feb 25, 2019 | Oct 4, 2017 |
| Redhat_linux | — | Upgrade golang-binUpgrade golang-docsUpgrade golang-srcUpgrade golang-testsUpgrade golang-miscUpgrade golang | Aug 2, 2018 | Aug 1, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 5, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub