Go Standard Library Net Http Internal vulnerabilities
2 known vulnerabilities affecting go_standard_library/net_http_internal.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-22871CRITICALCVSS 9.1fixed in 1.23.8≥ 1.24.0-0, < 1.24.22025-04-08
CVE-2025-22871 [CRITICAL] CVE-2025-22871: The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size li
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
cvelistv5nvd
CVE-2023-39326MEDIUMCVSS 5.3fixed in 1.20.12≥ 1.21.0-0, < 1.21.52023-12-06
CVE-2023-39326 [MEDIUM] CVE-2023-39326: A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or respo
A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a reques
cvelistv5nvd