CVE-2021-4236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
27/12/2022
Last modified:
11/04/2025

Description

Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:web_project:web:*:*:*:*:*:go:*:* 1.4.0 (including) 1.5.2 (excluding)