Description Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Exploitability: 3.9 | Impact: 2.5 Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages3 packages
🔴 Vulnerability Details6 OSV golang-1.13, golang-1.16 vulnerabilities ↗ 2024-01-09 ▶ OSV golang-1.18 vulnerabilities ↗ 2023-04-25 ▶ GHSA GHSA-5hv8-7f46-fxf6: Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1 ↗ 2022-08-11 ▶ OSV CVE-2022-1705: Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1 ↗ 2022-08-10 ▶ CVEList Improper sanitization of Transfer-Encoding headers in net/http ↗ 2022-08-09 ▶ Show 1 more
📋 Vendor Advisories6 Palo Alto PAN-SA-2024-0013 Informational Bulletin: Impact of OSS CVEs in PAN-OS ↗ 2024-11-01 ▶ Ubuntu Go vulnerabilities ↗ 2024-01-09 ▶ Ubuntu Go vulnerabilities ↗ 2023-04-25 ▶ Microsoft Improper sanitization of Transfer-Encoding headers in net/http ↗ 2022-08-09 ▶ Red Hat golang: net/http: improper sanitization of Transfer-Encoding header ↗ 2022-07-12 ▶ Show 1 more