← Back to CVE List

CVE-2022-30591

Published: 2022-07-06T12:15Z
Last Modified: 2024-11-21T07:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List > MITRE Terms of Use apply – see LICENSE‑MITRE.txt