GHSA-9f57-9rhg-4hvm

Suggest an improvement
Source
https://github.com/advisories/GHSA-9f57-9rhg-4hvm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-9f57-9rhg-4hvm/GHSA-9f57-9rhg-4hvm.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9f57-9rhg-4hvm
Aliases
Published
2025-02-20T03:32:03Z
Modified
2025-02-20T20:42:06.547665Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Kwik hash collision vulnerability
Details

An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs).

Database specific
{
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": "2025-02-20T03:15:12Z",
    "github_reviewed_at": "2025-02-20T20:18:50Z",
    "cwe_ids": [
        "CWE-407"
    ]
}
References

Affected packages

Maven / tech.kwik:kwik

Package

Name
tech.kwik:kwik
View open source insights on deps.dev
Purl
pkg:maven/tech.kwik/kwik

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.1

Affected versions

0.*
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.8.10
0.8.11
0.8.12
0.8.13
0.9
0.9.1
0.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-9f57-9rhg-4hvm/GHSA-9f57-9rhg-4hvm.json"