CVE-2017-1000098: Golang Go

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

Affected products

  • Golang Go: before 1.6.4 (fixed in 1.6.4); from 1.7, before 1.7.4 (fixed in 1.7.4)

Published 2017-10-05. Last modified 2026-06-17.