{"id":"CVE-2023-37788","aliases":["GHSA-4r8x-2p26-976p","GO-2023-1941"],"title":"goproxy Denial of Service vulnerability","summary":"goproxy Denial of Service vulnerability","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"elazarl","product":"github.com/elazarl/goproxy","ecosystem":"go","affected":["github.com/elazarl/goproxy < 0.0.0-20230731152917-f99041a5c027"],"patched":["github.com/elazarl/goproxy 0.0.0-20230731152917-f99041a5c027"],"published":"2023-07-18","updated":"2026-08-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4r8x-2p26-976p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37788"},{"url":"https://github.com/elazarl/goproxy/issues/502"},{"url":"https://github.com/elazarl/goproxy/pull/507"},{"url":"https://github.com/elazarl/goproxy"}],"tags":["osv","go"],"epss":0.00979,"epssPercentile":0.60706,"ingestedAt":"2026-08-07T19:14:15.736Z","slug":"CVE-2023-37788","body":"## Overview\n\ngoproxy prior to pseudoversion 0.0.0-20230731152917-f99041a5c027 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.\n\n## Affected packages\n\n- `github.com/elazarl/goproxy < 0.0.0-20230731152917-f99041a5c027`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/elazarl/goproxy 0.0.0-20230731152917-f99041a5c027`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}