CVE-2023-29406

CVSS v3.1 6.5 (Medium)
65% Progress
EPSS 0.12 % (47th)
0.12% Progress
Affected Products 1
Advisories 41

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

Weaknesses
CWE-436
Interpretation Conflict
CVE Status
PUBLISHED
CNA
Go Project
Published Date
2023-07-11 20:15:10
(14 months ago)
Updated Date
2023-11-25 11:15:14
(9 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Golang Go prior 1.19.11 version cpe:2.3:a:golang:go < 1.19.11
  Golang Go from 1.20.0 version and prior 1.20.6 version cpe:2.3:a:golang:go >= 1.20.0 < 1.20.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...