Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade plug to version 1.15.5, 1.16.4, 1.17.2, 1.18.3, 1.19.3 or higher.
plug is a specification and conveniences for composable modules between web applications.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the nested-parameter decoder (Plug.Conn.Query). An attacker can exhaust server resources and render the application unresponsive by sending specially crafted requests with a large number of nested parameters.