← Πίσω στην αναζήτηση CVE

CVE-2026-45047

bird-lg-go

Περιγραφή

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e.g., several Gigabytes of padding) over a single TCP connection. Because Go-s JSON decoder attempts to allocate memory for the entire parsed structure, this rapidly exhausts the host-s physical RAM or container limits, leading to an unrecoverable fatal error: runtime: out of memory. This vulnerability is fixed in 1.4.5.

CVSS 7.5EPSS 0.441%Κίνδυνος 0.78
Προβολή πηγής
Δημοσίευση
2026-05-27 18:16:24
Επηρεαζόμενες εκδόσεις
<1.4.5
Τύπος
Package
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H