Skip to content

Vulnerability in signoz project #10661

@ankitdn

Description

@ankitdn

While working in signoz project, I found that the application uses github.com/russellhaering/gosaml2, which is affected by a denial-of-service vulnerability in its AES-CBC decryption logic. The issue occurs in the DecryptBytes function, where malformed input can result in empty data after trimming, leading to an index out-of-range panic.

CVE Report
CVE Link

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filegoPull requests that update Go code

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions