{"id":"CVE-2021-23409","details":"The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header.","aliases":["GHSA-xcf7-q56x-78gh","GO-2022-0233"],"modified":"2026-07-09T11:24:03.967787Z","published":"2021-07-21T07:15:07.547Z","references":[{"type":"ADVISORY","url":"https://github.com/pires/go-proxyproto/releases/tag/v0.6.0"},{"type":"REPORT","url":"https://github.com/pires/go-proxyproto/issues/65"},{"type":"FIX","url":"https://github.com/pires/go-proxyproto/pull/74"},{"type":"FIX","url":"https://github.com/pires/go-proxyproto/pull/74/commits/cdc63867da24fc609b727231f682670d0d1cd346"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMPIRESGOPROXYPROTO-1316439"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pires/go-proxyproto","events":[{"introduced":"0"},{"fixed":"3aa7ea95a821cf534fae576651e2ca11f222a4e3"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:go-proxyproto_project:go-proxyproto:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.6.0"}]}}],"versions":["v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.3","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23409.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}