An open index of dependabot pull requests across open source projects.

Docker Registry has Allocation of Resources Without Limits or Throttling

GHSA-h62f-wm92-2cmw CVE-2017-11468
Description:

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

Specific Go Packages Affected

github.com/docker/distribution/registry/storage
github.com/docker/distribution/registry/handlers

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
go github.com/docker/distribution < 2.7.0-rc.0
2.7.0-rc.0
Related Dependabot Pull Requests