{"id":"CVE-2023-2253","aliases":["GHSA-hqxw-f8mx-cpmw","GO-2023-1772"],"url":"https://o3.security/vulnerability/CVE-2023-2253","summary":"distribution catalog API endpoint can lead to OOM via malicious user input","details":"A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.","published":"2023-06-06T20:15:12.493Z","modified":"2026-04-16T04:35:21.290545915Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/docker/distribution","fixedVersion":"2.8.2-beta.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00035.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2189886"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T04:35:21.290545915Z"}}