CVE-2019-9741
published 2019-03-13CVE-2019-9741: An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument…
PriorityP431medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.35%
81.7th percentile
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| golang | go | — | — |
| msrc | azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-tensorboard_2.16.2-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| redhat | developer_tools | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang: CRLF injection in net/http
vendor_redhat·2019-03-13·CVSS 6.1
CVE-2019-9741 [MEDIUM] CWE-113 golang: CRLF injection in net/http
golang: CRLF injection in net/http
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
Statement: This issue affects the versions of golang as shipped with Red Hat Ceph Storage 2 and 3, and Red Hat Gluster Storage 3 as the vulnerable code is present.
Package: golang (Red Hat Ceph Storage 2) - Will not fix
Package: golang (Red Hat Ceph Storage 3) - Will not fix
Package: golang (Red Hat Enterprise Linux 7) - Will not fix
Package: golang (Red Hat OpenStack Platform 8 (Liberty) Operational Tools) - Will not fix
Package: golang (Red Hat OpenStack Platform 9 (Mitaka) Operational Tools) - Will not fix
Package:
Microsoft
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the second argument to http.NewRequest with \r\n followed by an
vendor_msrc·2019-03-12·CVSS 6.1
CVE-2019-9741 [MEDIUM] CWE-93 An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the second argument to http.NewRequest with \r\n followed by an
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products i
GHSA
GHSA-46v6-2c7g-7hfg: An issue was discovered in net/http in Go 1
ghsa_unreviewed·2022-05-13
CVE-2019-9741 [MEDIUM] CWE-93 GHSA-46v6-2c7g-7hfg: An issue was discovered in net/http in Go 1
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
OSV
CVE-2019-9741: An issue was discovered in net/http in Go 1
osv·2019-03-13·CVSS 6.1
CVE-2019-9741 [MEDIUM] CVE-2019-9741: An issue was discovered in net/http in Go 1
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9741 golang: CRLF injection in net/http [epel-all]
bugzilla·2019-03-13·CVSS 6.1
CVE-2019-9741 [MEDIUM] CVE-2019-9741 golang: CRLF injection in net/http [epel-all]
CVE-2019-9741 golang: CRLF injection in net/http [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. Whi
Bugzilla
CVE-2019-9741 golang: CRLF injection in net/http
bugzilla·2019-03-13·CVSS 6.1
CVE-2019-9741 [MEDIUM] CVE-2019-9741 golang: CRLF injection in net/http
CVE-2019-9741 golang: CRLF injection in net/http
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
Reference:
https://github.com/golang/go/issues/30794
Discussion:
Created golang tracking bugs for this issue:
Affects: fedora-all [bug 1688233]
---
Created golang tracking bugs for this issue:
Affects: epel-all [bug 1688234]
---
Upstream fixes for Go 1.12.1:
https://github.com/golang/go/commit/829c5df58694b3345cb5ea41206783c8ccf5c3ca#diff-b97af51863ce82bf2a13003b52034aa9
https://github.com/golang/go/commit/f1d662f34788f4a5f087581d0951cdf4e0f6e708#diff-b97af51863ce82bf2a13003b52034aa9
---
Statement:
Bugzilla
CVE-2019-9741 golang: CRLF injection in net/http [fedora-all]
bugzilla·2019-03-13·CVSS 6.1
CVE-2019-9741 [MEDIUM] CVE-2019-9741 golang: CRLF injection in net/http [fedora-all]
CVE-2019-9741 golang: CRLF injection in net/http [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
http://www.securityfocus.com/bid/107432https://access.redhat.com/errata/RHSA-2019:1300https://access.redhat.com/errata/RHSA-2019:1519https://github.com/golang/go/issues/30794https://lists.debian.org/debian-lts-announce/2019/04/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOOVCEPQM7TZA6VEZEEB7QZABXNHQEHH/http://www.securityfocus.com/bid/107432https://access.redhat.com/errata/RHSA-2019:1300https://access.redhat.com/errata/RHSA-2019:1519https://github.com/golang/go/issues/30794https://lists.debian.org/debian-lts-announce/2019/04/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOOVCEPQM7TZA6VEZEEB7QZABXNHQEHH/
2019-03-13
Published