Description
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.
Remediation
References
Related Vulnerabilities
WordPress Plugin ImageLinks Interactive Image Builder for WordPress Cross-Site Scripting (1.5.2)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2022-4203)
Internet Information Services Other Vulnerability (CVE-2000-0886)
WordPress Plugin Change WordPress Login Logo Cross-Site Scripting (1.1.4)
WordPress Plugin WP Reactions Lite Cross-Site Scripting (1.3.5)