Closed NazariiDenha closed 2 months ago
Semgrep found 6 ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2
findings:
Risk: Affected versions of golang.org/x/net, golang.org/x/net/http2, and net/http are vulnerable to Uncontrolled Resource Consumption. An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.
Fix: Upgrade this library to at least version 0.23.0 at go-ethereum/go.mod:103.
Reference(s): https://github.com/advisories/GHSA-4v7x-pqxf-cx7m, CVE-2023-45288
Ignore this finding from ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2.
1. Purpose or design rationale of this PR
as discussed here and also as needed feature in future reduce bridge latency project adding beacon node client to fetch blobs
2. PR title
Your PR title must follow conventional commits (as we are doing squash merge for each PR), so it must start with one of the following types:
3. Deployment tag versioning
Has the version in
params/version.go
been updated?4. Breaking change label
Does this PR have the
breaking-change
label?