{"id":"GO-2023-2388","summary":"eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations in knative.dev/eventing-github","details":"eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations in knative.dev/eventing-github","aliases":["GHSA-v7hc-87jc-qrrr"],"modified":"2026-03-03T04:55:09.917706Z","published":"2024-08-21T14:30:24Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2023-2388"},"references":[{"type":"ADVISORY","url":"https://github.com/knative-extensions/eventing-github/security/advisories/GHSA-v7hc-87jc-qrrr"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/commit/ea5cb8b25fc3410dde45ce2eb95454e4cfe77c40"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/442"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/446"},{"type":"WEB","url":"https://github.com/knative-extensions/eventing-github/pull/447"}],"affected":[{"package":{"name":"knative.dev/eventing-github","ecosystem":"Go","purl":"pkg:golang/knative.dev/eventing-github"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.39.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2023-2388.json"}}],"schema_version":"1.7.3"}