-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from using deprecated ioutil.ReadAll() which reads entire request bodies into memory. The commit diff shows replacements of ioutil.ReadAll() with io.ReadAll combined with http.MaxBytesReader in multiple event source handlers. The affected components listed in the advisory (AWS SNS, Bitbucket, Gitlab, etc.) correspond to these patched files. Each identified function was directly modified in the security patch, indicating they were vulnerable endpoints allowing DoS via large payloads.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/argoproj/argo-events | go | < 1.7.1 | 1.7.1 |
Ongoing coverage of React2Shell