CVE-2022-32149
Vulnerability Summary
Timeline
Description
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.55%• Percentile: 74%
Techniques & Countermeasures
- CWE-772•Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Affected Systems
- chainguard•dex-k8s-authenticator
< 0
- chainguard•dynamic-localpv-provisioner
< 3.4.1-r3
- chainguard•dynamic-localpv-provisioner-fips
< 3.5.0-r0
- chainguard•gitleaks
< 8.18.2-r1
- chainguard•grpcurl
< 1.8.7-r7
- chainguard•hey
< 0.1.4-r3
- chainguard•k3d
< 5.6.0-r11
- chainguard•k3d-proxy
< 5.6.0-r11
- chainguard•k3d-tools
< 5.6.0-r11
- chainguard•kube-state-metrics-2.6
< 2.6.0-r1
- chainguard•kubeflow
< 1.10.0-r2
- chainguard•kubeflow-access-management
< 1.10.0-r2
- chainguard•kubeflow-access-management-compat
< 1.10.0-r2
- chainguard•kubeflow-access-management-fips
< 1.10.0-r2
- chainguard•kubeflow-access-management-fips-compat
< 1.10.0-r2
- chainguard•kubeflow-admission-webhook
< 1.10.0-r2
- chainguard•kubeflow-admission-webhook-compat
< 1.10.0-r2
- chainguard•kubeflow-admission-webhook-fips
< 1.10.0-r2
- chainguard•kubeflow-admission-webhook-fips-compat
< 1.10.0-r2
- chainguard•kubeflow-fips
< 1.10.0-r2
- chainguard•kubeflow-notebook-controller
< 1.10.0-r2
- chainguard•kubeflow-notebook-controller-compat
< 1.10.0-r2
- chainguard•kubeflow-notebook-controller-fips
< 1.10.0-r2
- chainguard•kubeflow-notebook-controller-fips-compat
< 1.10.0-r2
- chainguard•kubeflow-profile-controller
< 1.10.0-r2
- chainguard•kubeflow-profile-controller-compat
< 1.10.0-r2
- chainguard•kubeflow-profile-controller-fips
< 1.10.0-r2
- chainguard•kubeflow-profile-controller-fips-compat
< 1.10.0-r2
- chainguard•kubeflow-pvcviewer-controller
< 1.10.0-r2
- chainguard•kubeflow-pvcviewer-controller-compat
< 1.10.0-r2
- chainguard•kubeflow-pvcviewer-controller-fips
< 1.10.0-r2
- chainguard•kubeflow-pvcviewer-controller-fips-compat
< 1.10.0-r2
- chainguard•kubeflow-tensorboard-controller
< 1.10.0-r2
- chainguard•kubeflow-tensorboard-controller-compat
< 1.10.0-r2
- chainguard•kubeflow-tensorboard-controller-fips
< 1.10.0-r2
- chainguard•kubeflow-tensorboard-controller-fips-compat
< 1.10.0-r2
- chainguard•php-fpm_exporter
< 2.2.0-r8
- chainguard•prometheus-postgres-exporter-0.10
< 0
- chainguard•terraform-provider-sendgrid
< 1.0.1-r1
- chainguard•terraform-provider-sendgrid-fips
< 1.0.1-r1
- chainguard•vt-cli
< 1.0.0-r3
- wolfi•dynamic-localpv-provisioner
< 3.4.1-r3
- wolfi•gitleaks
< 8.18.2-r1
- wolfi•grpcurl
< 1.8.7-r7
- wolfi•hey
< 0.1.4-r3
- wolfi•k3d
< 5.6.0-r11
- wolfi•k3d-proxy
< 5.6.0-r11
- wolfi•k3d-tools
< 5.6.0-r11
- wolfi•kubeflow
< 1.10.0-r2
- wolfi•kubeflow-access-management
< 1.10.0-r2
Showing first 50 affected entries in server-rendered view.
References (20)
- https://go.dev/issue/56152
- https://go.dev/cl/442235
- https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ
- https://pkg.go.dev/vuln/GO-2022-1059
- https://security.netapp.com/advisory/ntap-20230203-0006/
- https://nvd.nist.gov/vuln/detail/CVE-2022-32149
- https://github.com/golang/go/issues/56152
- https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c
- https://github.com/golang/text
- https://security.netapp.com/advisory/ntap-20230203-0006
- https://access.redhat.com/errata/RHSA-2024:1994
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=2134010
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1994.json
- https://access.redhat.com/security/cve/CVE-2022-32149
- https://www.cve.org/CVERecord?id=CVE-2022-32149
- https://groups.google.com/g/golang-dev/c/qfPIly0X7aU
- https://security-tracker.debian.org/tracker/CVE-2022-32149
- https://pkg.go.dev
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32149.json