Total vulnerabilities in the database
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.
Software | From | Fixed in |
---|---|---|
golang / go | 1.21.0 | 1.21.1 |