YARP Denial of Service Vulnerability
High severity
GitHub Reviewed
Published
Apr 12, 2022
in
microsoft/reverse-proxy
•
Updated Jan 27, 2023
Package
Affected versions
< 1.0.1
= 1.1.0-rc.1.22152.1
Patched versions
1.0.1
1.1.0-rc.1.22211.2
Description
Published by the National Vulnerability Database
Apr 15, 2022
Published to the GitHub Advisory Database
Apr 22, 2022
Reviewed
Apr 22, 2022
Last updated
Jan 27, 2023
Impact
A denial of service vulnerability exists in how YARP processes input.
Patches
If you're using YARP
1.0.0
, you should update to NuGet package version1.0.1
.If you're using YARP
1.1.0-RC.1
, you should update to NuGet package version1.1.0-rc.1.22211.2
.You can do so by updating the
PackageReference
in your.csproj
fileor by selecting
1.0.1
in the NuGet UI inside Visual Studio (Manage NuGet Packages
/Updates
)References
CVE-2022-26924
References