# Resty CVE-2023-45286 Vulnerability

**URL:** https://discuss.prometheus.io/t/resty-cve-2023-45286-vulnerability/2066
**Category:** General Help/Support
**Created:** [December 20, 2023, 7:13am UTC](https://discuss.prometheus.io/t/resty-cve-2023-45286-vulnerability/2066 "2023-12-20T07:13:54Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Hench10](https://dub1.discourse-cdn.com/flex017/user_avatar/discuss.prometheus.io/hench10/32/871_2.png) [@Hench10](https://discuss.prometheus.io/u/Hench10)
#### Post date: [December 20, 2023, 7:13am UTC](https://discuss.prometheus.io/t/resty-cve-2023-45286-vulnerability/2066/1 "2023-12-20T07:13:54Z")

</div>

Will prometheus be affected by CVE-2023-45286?

> **[GO-2023-2328 - Go Packages](https://pkg.go.dev/vuln/GO-2023-2328)**
>
> Go is an open source programming language that makes it easy to build simple, reliable, and efficient software.

---

<div class="post-metadata">

### Author: ![SuperQ](https://dub1.discourse-cdn.com/flex017/user_avatar/discuss.prometheus.io/superq/32/4_2.png) [@SuperQ](https://discuss.prometheus.io/u/SuperQ)
#### Post date: [December 20, 2023, 7:19am UTC](https://discuss.prometheus.io/t/resty-cve-2023-45286-vulnerability/2066/2 "2023-12-20T07:19:41Z")

</div>

It looks like that library is used by the linode discovery plugin. It would take some detailed analysis to see if there is an actual vulnerability. Too difficult to tell from just the dependency tree.
