github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS)
21
Low Risk
Affected versions of this package are vulnerable to denial of service (DoS) due to a flaw in the sign function when using ed25519 with a key that is not 64 bytes. Supplying such an invalid key triggers a panic, causing the application to crash and become unavailable.
You are affected if you are using a vulnerable version of the package.
github.com/yaronf/httpsign is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.3.2.
Upgrade the github.com/yaronf/httpsign library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant