GO-2025-4233

Source
https://pkg.go.dev/vuln/GO-2025-4233
Import Source
https://vuln.go.dev/ID/GO-2025-4233.json
JSON Data
https://api.test.osv.dev/v1/vulns/GO-2025-4233
Aliases
Published
2025-12-15T20:37:41Z
Modified
2025-12-15T21:11:03.142548Z
Summary
HTTP/3 QPACK Header Expansion DoS in github.com/quic-go/quic-go
Details

HTTP/3 QPACK Header Expansion DoS in github.com/quic-go/quic-go

Database specific
{
    "url": "https://pkg.go.dev/vuln/GO-2025-4233",
    "review_status": "REVIEWED"
}
References

Affected packages

Go / github.com/quic-go/quic-go

Package

Name
github.com/quic-go/quic-go
View open source insights on deps.dev
Purl
pkg:golang/github.com/quic-go/quic-go

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.57.0

Ecosystem specific

{
    "imports": [
        {
            "symbols": [
                "ClientConn.OpenRequestStream",
                "ClientConn.RoundTrip",
                "ConfigureTLSConfig",
                "Conn.OpenStream",
                "Conn.OpenStreamSync",
                "Conn.OpenUniStream",
                "Conn.OpenUniStreamSync",
                "Conn.decodeTrailers",
                "ErrCode.String",
                "Error.Error",
                "ListenAndServeQUIC",
                "ListenAndServeTLS",
                "ParseCapsule",
                "RequestStream.CancelRead",
                "RequestStream.CancelWrite",
                "RequestStream.Close",
                "RequestStream.Read",
                "RequestStream.ReadResponse",
                "RequestStream.SendRequestHeader",
                "RequestStream.Write",
                "Server.Close",
                "Server.ListenAndServe",
                "Server.ListenAndServeTLS",
                "Server.Serve",
                "Server.ServeListener",
                "Server.ServeQUICConn",
                "Server.Shutdown",
                "Server.handleRequest",
                "Server.maxHeaderBytes",
                "Stream.Read",
                "Stream.Write",
                "Transport.Close",
                "Transport.CloseIdleConnections",
                "Transport.NewClientConn",
                "Transport.RoundTrip",
                "Transport.RoundTripOpt",
                "body.Close",
                "body.Read",
                "cancelingReader.Read",
                "countingByteReader.Read",
                "countingByteReader.ReadByte",
                "errConnUnusable.Error",
                "exactReader.Read",
                "frameParser.ParseNext",
                "gzipReader.Close",
                "gzipReader.Read",
                "hijackableBody.Close",
                "hijackableBody.Read",
                "parseHeaders",
                "requestFromHeaders",
                "requestWriter.WriteRequestHeader",
                "responseWriter.Flush",
                "responseWriter.FlushError",
                "responseWriter.HTTPStream",
                "responseWriter.Write",
                "responseWriter.WriteHeader",
                "roundTripperWithCount.Close",
                "stateTrackingStream.CancelRead",
                "stateTrackingStream.CancelWrite",
                "stateTrackingStream.Close",
                "stateTrackingStream.Read",
                "stateTrackingStream.Write",
                "tracingReader.Read",
                "updateResponseFromHeaders"
            ],
            "path": "github.com/quic-go/quic-go/http3"
        }
    ]
}

Database specific

source

"https://vuln.go.dev/ID/GO-2025-4233.json"