Asymmetric denial of service In github.com/ethereum/go-ethereum
Description
go-ethereum vulnerable to denial of service via crafted GraphQL query
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query.
NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | - | ||
go | 1.13.5 | ||
go | - |
Aliases
1. 2. 3. 4.
References
1. 2. 3.