The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439 | third party advisory patch |
https://github.com/pires/go-proxyproto/releases/tag/v0.6.0 | third party advisory release notes |
https://github.com/pires/go-proxyproto/issues/65 | third party advisory issue tracking |
https://github.com/pires/go-proxyproto/pull/74 | third party advisory patch |
https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346 | third party advisory patch |