HTTP request smuggling In golang-1.15
Description
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | 1.19~rc1-1 | ||
go | 1.17.12 | ||
rpm rhel9 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | 0:0.0.99.3-5.el9 | ||
rpm rhel8 | - | - | |
rpm rhel8 | 0:1.17.12-1.module+el8.6.0+16014+a372c00b | ||
rpm rhel9 | 0:3.2.0-3.el9 | ||
rpm rhel8 | - | - |
1-10 of 23
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5.