cvss not scored
how bad it is if exploited, out of 10
epss not scored
chance of exploitation in the next 30 days
xyz score not scored
CyberXYZ composite, out of 10
fig. 01 — BIT-golang-2023-39326, the advisory selected below
// advisories BIT-golang-2023-39326 UNKN BIT-golang-2023-39319 UNKN BIT-golang-2023-29403 UNKN BIT-golang-2023-29400 UNKN BIT-golang-2022-41725 UNKN BIT-golang-2022-41720 UNKN BIT-golang-2022-2879 UNKN BIT-golang-2022-32148 UNKN BIT-golang-2022-30580 UNKN BIT-golang-2022-30635 UNKN BIT-golang-2022-1962 UNKN BIT-golang-2022-28131 UNKN BIT-golang-2022-30633 UNKN BIT-golang-2022-30630 UNKN BIT-golang-2021-44717 UNKN BIT-golang-2020-15586 UNKN BIT-golang-2021-33198 UNKN BIT-golang-2021-34558 UNKN BIT-golang-2020-24553 UNKN BIT-golang-2021-27919 UNKN
BIT-golang-2023-39326 UNKNOWN A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body.
Affected >=0, <1.20.12, >=1.21.0-0, <1.21.5 Fixed in not stated Published 2023-12-06 Source osv // ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so nuget packages are not covered.
Checked 2026-09-22 at 01:36 UTC. The most recent advisory here was published 2023-12-06. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page