-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability specifically affects ListObjects calls and manifests as resource retention after response completion. In Go implementations, this typically indicates a handler function failing to properly manage request-scoped resources. The pattern matches common goroutine leaks or unclosed resources in HTTP handlers. While exact code changes aren't available, the vulnerability's specific association with ListObjects operations and the nature of the fix (resource management) strongly implicate the core handler function.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/openfga/openfga | go | < 1.3.4 | 1.3.4 |
Ongoing coverage of React2Shell