The Go Proxyproto Project maintains a narrowly scoped library that implements the PROXY protocol for connection metadata forwarding, used in load balancers and reverse proxies to preserve client information across protocol layers. Vulnerabilities in this component are tracked at the library level; defenders should focus on identifying and patching downstream products that bundle or depend on this library rather than tracking the library itself. Current exposure levels and vulnerability details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Go Proxyproto Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23409HIGH The package github.com/pires/go-proxyproto before 0.6.0 are vulnerable to Denial of Service (DoS) via creating connections without the proxy protocol header. | Jul 21, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-23351MEDIUM The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Re | Mar 8, 2021 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Go Proxyproto Project.
Media articles that mention a CVE ID that affects a product developed by Go Proxyproto Project — matched by CVE ID, not by vendor name.