{"id":"UBUNTU-CVE-2022-21698","details":"client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.","modified":"2026-05-20T16:06:41.357750433Z","published":"2022-02-15T16:15:00Z","upstream":["CVE-2022-21698"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-21698"},{"type":"REPORT","url":"https://github.com/prometheus/client_golang/security/advisories/GHSA-cg3q-j54f-5p7p"},{"type":"REPORT","url":"https://github.com/prometheus/client_golang/pull/962"},{"type":"REPORT","url":"https://github.com/prometheus/client_golang/pull/987"},{"type":"REPORT","url":"https://github.com/prometheus/client_golang/releases/tag/v1.11.1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-21698"}],"affected":[{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.0-1","0.8.0-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.8.0-2","binary_name":"golang-github-prometheus-client-golang-dev"},{"binary_version":"0.8.0-2","binary_name":"golang-prometheus-client-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}},{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.2-0ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-prometheus-client-golang-dev","binary_version":"0.9.2-0ubuntu3"},{"binary_name":"golang-prometheus-client-dev","binary_version":"0.9.2-0ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}},{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.0-2","1.11.0-3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-prometheus-client-golang-dev","binary_version":"1.11.0-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}},{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.0-4","1.17.0-2","1.18.0-2","1.18.0-3"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-prometheus-client-golang-dev","binary_version":"1.18.0-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}},{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-prometheus-client-golang-dev","binary_version":"1.21.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}},{"package":{"name":"golang-github-prometheus-client-golang","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/golang-github-prometheus-client-golang?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21.1-1","1.23.2-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-github-prometheus-client-golang-dev","binary_version":"1.23.2-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21698.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}