Beschreibung
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e.g., several Gigabytes of padding) over a single TCP connection. Because Go-s JSON decoder attempts to allocate memory for the entire parsed structure, this rapidly exhausts the host-s physical RAM or container limits, leading to an unrecoverable fatal error: runtime: out of memory. This vulnerability is fixed in 1.4.5.
CVSS 7.5EPSS 0.441%Risiko 0.78
Quelle öffnen- Veröffentlicht
- 2026-05-27 18:16:24
- Betroffene Versionen
- <1.4.5
- Typ
- Package
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H