Skip to content
This repository has been archived by the owner on Oct 12, 2023. It is now read-only.

Vulnerability in nhooyr.io/websocket #227

Closed
princjef opened this issue May 14, 2021 · 2 comments
Closed

Vulnerability in nhooyr.io/websocket #227

princjef opened this issue May 14, 2021 · 2 comments

Comments

@princjef
Copy link
Member

There is a vulnerability in the current version of nhooyr.io/websocket that is used by this package (1.8.6), which can potentially cause a DoS vulnerability. It's admittedly a low risk problem here in practice, but updating to 1.8.7+ makes the automated security scanning tools happy.

Here are the details for the CVE: https://snyk.io/vuln/SNYK-GOLANG-NHOOYRIOWEBSOCKET-1244972

@jhendrixMSFT
Copy link
Member

Fixed in v0.11.4

@jhendrixMSFT
Copy link
Member

Fixed in v0.11.4

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants