This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.

github.com/valyala/fasthttp known bugs

go

2 known bugs in github.com/valyala/fasthttp, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

2
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
highany1.34.0
Path traversal in github.com/valyala/fasthttp
The package github.com/valyala/fasthttp before 1.34.0 is vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue impacts Windows users only.
fixedosv:GHSA-fx95-883v-4q4h
mediumany1.34.0
Path traversal in github.com/valyala/fasthttp
The fasthttp.FS request handler is vulnerable to directory traversal attacks on Windows systems, and can serve files from outside the provided root directory. URL path normalization does not handle Windows path separators (backslashes), permitting an attacker to construct requests with relative paths.
fixedosv:GO-2022-0355
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/go/github.com/valyala/fasthttp
github.com/valyala/fasthttp bugs — known issues per version | DepScope | DepScope