VYPR
High severityNVD Advisory· Published Nov 19, 2019· Updated Sep 16, 2024

A forged route service request using an invalid nonce can cause the gorouter to panic and crash

CVE-2019-11289

Description

Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
code.cloudfoundry.org/gorouterGo
< 0.0.0-20191101214924-b1b5c44e050f0.0.0-20191101214924-b1b5c44e050f

Affected products

2

Patches

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.