GHSA-322p-rrj6-j44g

Suggest an improvement
Source
https://github.com/advisories/GHSA-322p-rrj6-j44g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-322p-rrj6-j44g/GHSA-322p-rrj6-j44g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-322p-rrj6-j44g
Aliases
Published
2026-05-11T06:31:33Z
Modified
2026-06-25T18:56:33Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
Details

A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives.go of the component zerogod IPP Service. Performing a manipulation results in integer coercion error. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is named 3731d5576cffae9eefe3721cd46a40933304129f. To fix this issue, it is recommended to deploy a patch.

Database specific
{
    "cwe_ids":  [
        "CWE-190",
        "CWE-192"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-14T21:14:53Z",
    "nvd_published_at":  "2026-05-11T06:16:09Z",
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/bettercap/bettercap/v2

Package

Name
github.com/bettercap/bettercap/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/bettercap/bettercap/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.41.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-322p-rrj6-j44g/GHSA-322p-rrj6-j44g.json"