Systems that run distribution built after a specific commit running on memory-restricted environments can suffer from denial of service by a crafted malicious /v2/_catalog API endpoint request.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1772" }