[GO-2022-0525] Improper sanitization of Transfer-Encoding headers in net/http

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

The HTTP/1 client accepted some invalid Transfer-Encoding headers as indicating
a "chunked" encoding. This could potentially allow for request smuggling, but
only if combined with an intermediate server that also improperly failed to
reject the header as invalid.

Package Affected Version
pkg:golang/net/http >= 1.18.3, < 1.17.12
pkg:golang/net/http >= 1.18.3, < 1.18.4
Package Fixed Version
pkg:golang/net/http = 1.17.12
pkg:golang/net/http = 1.18.4
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/net/http net http = 1.17.12
Affected pkg:golang/net/http net http >= 1.18.3 < 1.17.12
Fixed pkg:golang/net/http net http = 1.18.4
Affected pkg:golang/net/http net http >= 1.18.3 < 1.18.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...