{"id":"GHSA-8xc6-g8xw-h2c4","summary":"YARP Denial of Service Vulnerability","details":"### Impact\n\nA denial of service vulnerability exists in how YARP processes input.\n\n### Patches\n\nIf you're using YARP `1.0.0`, you should update to NuGet package version [`1.0.1`](https://www.nuget.org/packages/Yarp.ReverseProxy/1.0.1).\nIf you're using YARP `1.1.0-RC.1`, you should update to NuGet package version [`1.1.0-rc.1.22211.2`](https://www.nuget.org/packages/Yarp.ReverseProxy/1.1.0-rc.1.22211.2).\n\nYou can do so by updating the `PackageReference` in your `.csproj` file\n```diff\n\u003cItemGroup\u003e\n- \u003cPackageReference Include=\"Yarp.ReverseProxy\" Version=\"1.0.0\" /\u003e\n- \u003cPackageReference Include=\"Yarp.Telemetry.Consumption\" Version=\"1.0.0\" /\u003e\n+ \u003cPackageReference Include=\"Yarp.ReverseProxy\" Version=\"1.0.1\" /\u003e\n+ \u003cPackageReference Include=\"Yarp.Telemetry.Consumption\" Version=\"1.0.1\" /\u003e\n\u003c/ItemGroup\u003e\n```\nor by selecting `1.0.1` in the NuGet UI inside Visual Studio (`Manage NuGet Packages` / `Updates`)\n![image](https://user-images.githubusercontent.com/25307628/162951795-a30f8ed7-77ef-4c4f-920e-58d9e1587ad1.png)\n\n### References\n\n[CVE-2022-26924](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26924)","aliases":["CVE-2022-26924"],"modified":"2024-12-05T05:26:59.037864Z","published":"2022-04-22T20:23:44Z","database_specific":{"github_reviewed_at":"2022-04-22T20:23:44Z","nvd_published_at":"2022-04-15T19:15:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/microsoft/reverse-proxy/security/advisories/GHSA-8xc6-g8xw-h2c4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26924"},{"type":"WEB","url":"https://github.com/microsoft/reverse-proxy/commit/11e6272da17beb03d0b44a19d3c4f1ffa52b7c38"},{"type":"PACKAGE","url":"https://github.com/microsoft/reverse-proxy"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26924"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26924"}],"affected":[{"package":{"name":"Yarp.ReverseProxy","ecosystem":"NuGet","purl":"pkg:nuget/Yarp.ReverseProxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-8xc6-g8xw-h2c4/GHSA-8xc6-g8xw-h2c4.json"}},{"package":{"name":"Yarp.ReverseProxy","ecosystem":"NuGet","purl":"pkg:nuget/Yarp.ReverseProxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0-rc.1.22152.1"},{"fixed":"1.1.0-rc.1.22211.2"}]}],"versions":["1.1.0-rc.1.22152.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-8xc6-g8xw-h2c4/GHSA-8xc6-g8xw-h2c4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}