Loading HuntDB...

GHSA-796p-jr7h-8vmq

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection from a client system (to any server), when that client system is concurrently obtaining TCP data at a slow rate from an attacker-controlled server, aka the "SnailLoad" issue. For example, the attack can begin by measuring RTTs via the TCP segments whose role is to provide an ACK control bit and an Acknowledgment Number.

Related CVEs

Key Information

GHSA ID
GHSA-796p-jr7h-8vmq
Published
July 3, 2024 6:47 PM
Last Modified
August 5, 2024 9:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.