CVE-2017-1000098: Golang Go
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.
Affected products
- Golang Go: before 1.6.4 (fixed in 1.6.4); from 1.7, before 1.7.4 (fixed in 1.7.4)
Published 2017-10-05. Last modified 2026-06-17.