Go Networking Flaws Expose Web Services to DoS and XSS Risks
Multiple vulnerabilities in Go's networking libraries impact HTTP/2 handling and HTML parsing, potentially enabling denial-of-service and cross-site scripting attacks.
TL;DR
- Four CVEs affect Go Networking's HTTP/2 and HTML processing capabilities.
- Vulnerabilities allow remote attackers to trigger DoS via resource exhaustion.
- One flaw enables potential XSS through improper HTML text node rendering.
- Issues include improper GOAWAY frame error handling and HPACK header decoding inefficiencies.
- Patched versions are available; developers should update immediately.
Recent security research has uncovered multiple vulnerabilities in Go’s core networking libraries that could pose serious threats to web applications built using the language. These issues primarily affect HTTP/2 communication and HTML parsing, opening doors for denial-of-service (DoS) and cross-site scripting (XSS) attacks.
The flaws range from improper error handling during HTTP/2 shutdown sequences to inefficient data processing that can be exploited to consume excessive system resources. One vulnerability even impacts how HTML content is rendered, creating opportunities for client-side injection attacks. Organizations relying on Go-based web services should take immediate action to mitigate these risks.
HTTP/2 Connection Handling Issues
- CVE-2022-27664 causes connections to hang due to improper server error handling after sending a GOAWAY frame.
- CVE-2022-41723 introduces quadratic complexity when decoding HPACK headers, allowing attackers to exhaust CPU resources.
HTML Parsing and XSS Vulnerabilities
- CVE-2023-3978 allows unescaped text outside the HTML namespace to be rendered literally, enabling XSS attacks.
- CVE-2024-45338 involves non-linear processing of HTML input lengths, contributing to resource exhaustion risks.
- An additional parsing flaw involving unquoted attributes in foreign content may also contribute to unexpected behavior.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.