github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to Infinite Loop
16
Low Risk
Affected versions of this package are vulnerable to an infinite loop in the internal/balancer/local_dc.go::getRandomEndpoints function. This flaw can cause the system to hang indefinitely, leading to a Denial of Service (DoS) by consuming resources and rendering the application unresponsive.
You are affected if you are using a version that falls within the vulnerable range.
github.com/ydb-platform/ydb-go-sdk/v3 is vulnerable to Infinite Loop in versions 3.26.0 - 3.99.2.
Upgrade the github.com/ydb-platform/ydb-go-sdk/v3 library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant