mostynb / go-grpc-compression

go gRPC encoding wrappers for some useful compression algorithms that are not available in google.golang.org/grpc
Apache License 2.0
17 stars 10 forks source link

CVE assignment for v1.2.2 susceptible to zstd decompression bombing DoS #30

Open rodmacedo1 opened 4 days ago

rodmacedo1 commented 4 days ago

Hi team. 👋🏼

Are you planning a CVE assignment for this security issue involving the v1.2.2 susceptible to zstd decompression bombing DoS (https://github.com/mostynb/go-grpc-compression/security/advisories/GHSA-87m9-rv8p-rgmg)

mostynb commented 4 days ago

Hi, I'm unsure of the process for requesting a CVE ID - or if this would be considered to be part of CVE-2024-36129?