CVE-2017-1000098

high
Published 2017-10-05 · Modified 2024-05-20
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
5.0
VIR risk
7.5

Description

Denial of service when parsing large forms in mime/multipart

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://golang.org/issue/17965

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://golang.org/cl/30410

OS impact

OSVersionStatusFixed in
arch archfixed2:1.8-1

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.7.0-0,<1.7.41.6.4

Application impact

VendorProductVersionsFixed
golanggo{"endExcluding":"1.6.4"}1.6.4

References

CWEs

CWE-769

Verify integrity in audit chain (admin only). AS-IS.