Skip to content

Conversation

@ericwb
Copy link
Contributor

@ericwb ericwb commented May 17, 2025

Several functions in the net/http package allow starting an http server but do not permit a way to set timeouts. This opens up the server to clients that might abuse it.

Rule ID: GO007

Several functions in the net/http package allow starting an http
server but do not permit a way to set timeouts. This opens up
the server to clients that might abuse it.

Rule ID: GO007

Signed-off-by: Eric Brown <eric.brown@securesauce.dev>
@ericwb ericwb force-pushed the net_http_no_timeout branch from 1d628a1 to 86aaaaf Compare May 17, 2025 04:48
@ericwb ericwb merged commit a20c2ab into securesauce:main May 17, 2025
20 of 21 checks passed
@ericwb ericwb deleted the net_http_no_timeout branch May 17, 2025 04:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant