{"id":"GO-2023-2017","summary":"Denial of service vulnerability in github.com/weaviate/weaviate","details":"A type conversion issue in Weaviate may allow a remote attack that would cause a denial of service.","aliases":["CVE-2023-38976","GHSA-8697-479h-5mfp"],"modified":"2026-02-04T02:51:25.798302Z","published":"2023-11-02T16:20:02Z","related":["CGA-wphh-9rvv-rpgj"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-2017"},"references":[{"type":"ADVISORY","url":"https://github.com/weaviate/weaviate/security/advisories/GHSA-8697-479h-5mfp"},{"type":"REPORT","url":"https://github.com/weaviate/weaviate/issues/3258"},{"type":"FIX","url":"https://github.com/weaviate/weaviate/pull/3431"},{"type":"FIX","url":"https://github.com/weaviate/weaviate/commit/2a7b208d9aca07e28969e3be82689c184ccf9118"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.18.6"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.19.13"},{"type":"WEB","url":"https://github.com/weaviate/weaviate/releases/tag/v1.20.6"}],"affected":[{"package":{"name":"github.com/weaviate/weaviate","ecosystem":"Go","purl":"pkg:golang/github.com/weaviate/weaviate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.6"},{"introduced":"1.19.0"},{"fixed":"1.19.13"},{"introduced":"1.20.0"},{"fixed":"1.20.6"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/weaviate/weaviate/adapters/handlers/rest","symbols":["Server.ConfigureAPI","Server.Serve","Server.SetAPI","handleUnbatchedGraphQLRequest"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2017.json"}}],"schema_version":"1.7.3"}