High severityNVD Advisory· Published Nov 19, 2019· Updated Sep 16, 2024
A forged route service request using an invalid nonce can cause the gorouter to panic and crash
CVE-2019-11289
Description
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.cloudfoundry.org/gorouterGo | < 0.0.0-20191101214924-b1b5c44e050f | 0.0.0-20191101214924-b1b5c44e050f |
Affected products
2- Cloud Foundry/Routingv5Range: All
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5- github.com/advisories/GHSA-5796-p3m6-9qj4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-11289ghsaADVISORY
- github.com/cloudfoundry/gorouter/commit/b1b5c44e050f73b399b379ca63a42a2c5780a83fghsaWEB
- pkg.go.dev/vuln/GO-2021-0102ghsaWEB
- www.cloudfoundry.org/blog/cve-2019-11289ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.