The httpSwagger package's HTTP handler provides WebDAV read/write access to an in-memory filesystem. An attacker can exploit this to cause memory exhaustion by uploading many files, XSS attacks by uploading malicious files, or other unexpected behaviors.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0427" }