CVE-2023-45288: HTTP/2 CONTINUATION flood in net/http
An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.
Other sources
This description was provided in the disclosure from VINCE:
The Go packages net/http and golang.org/x/net/http2 packages do not limit the number of CONTINUATION frames read for an HTTP/2 request, which permits an attacker to provide an arbitrarily large set of headers for a single request, that will be read, decoded, and subsequently discarded, which may result in excessive CPU consumption.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/golang.org/x/netto a version that resolves this vulnerability.Fixed in 0.23.0 - Upgrade
Upgrade
go/net/httpto a version that resolves this vulnerability.Fixed in 1.22.2 - Upgrade
Upgrade
go/golang.org/x/net/http2to a version that resolves this vulnerability.Fixed in 0.23.0 - Upgrade
Upgrade
go/net/httpto a version that resolves this vulnerability.Fixed in 1.21.9 - Upgrade
Upgrade
debian/golang-golang-x-netto a version that resolves this vulnerability.Fixed in 1:0.27.0-1 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.22.2 - Upgrade
Upgrade
redhat/golangto a version that resolves this vulnerability.Fixed in 1.21.9 - Upgrade
Upgrade
redhat/golang.org/x/netto a version that resolves this vulnerability.Fixed in 0.23.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.14.2-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.0.9-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.29.4-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.7-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.2-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.17-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.17.3-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.11.1-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.11.2-9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.29.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.12-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.2.0.azl2-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.2-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.28.4-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.1.2-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.9.5-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.6.2-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.0.24-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.11.1-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.29.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.25.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.4-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.62.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.0.10-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20240213-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.3.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.14.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.4-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.30.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.7-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.10.116-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.18-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.15.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.7.3-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 25.0.7-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.13-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.12.12-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.7-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.27.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.8.15-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.57.0-11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.12.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.6.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.24.2-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.0-13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 25.0.3-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.63.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.7.3-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.15.2-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.2.0.azl4-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.2-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.45.4-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.10.1-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.26-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.8.17-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.63.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.59.0-16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.0.9-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.37.9-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.17-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.24.0-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.1-1 - Upgrade
Upgrade
Go (net/http, golang.org/x/net/http2)to a version that resolves this vulnerability.Fixed in 1.22.2 - Upgrade
Upgrade
Go (net/http, golang.org/x/net/http2)to a version that resolves this vulnerability.Fixed in 1.21.9 - Upgrade
Upgrade
net/httpto a version that resolves this vulnerability.Patch CVE-2023-45288
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45288?
CVE-2023-45288 is considered a high-severity vulnerability as it allows an attacker to read arbitrary amounts of header data.
How do I fix CVE-2023-45288?
To fix CVE-2023-45288, upgrade to the latest versions of affected packages such as golang.org/x/net version 0.23.0 or net/http version 1.22.2.
Which software is affected by CVE-2023-45288?
Software affected by CVE-2023-45288 includes older versions of golang.org/x/net, net/http, and IBM Planning Analytics Workspace.
What types of attacks are possible with CVE-2023-45288?
An attacker can exploit CVE-2023-45288 by sending excessive CONTINUATION frames, which may lead to header data exposure.
Is there a workaround for CVE-2023-45288?
There is no documented workaround for CVE-2023-45288, so upgrading to the patched versions is advised.