PT-2026-108309 · Google · Go

·

CVE-2026-56866

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Go (affected versions not specified)
Description When http.Transport sends an HTTP/1 CONNECT request containing a non-empty Request.Body, the body is written directly to the connection without framing following the request headers. If the server responds to the CONNECT request with a non-2xx keep-alive response, the connection is returned to the idle pool. Since CONNECT requests are not expected to have a request body, the server may treat the remaining body bytes as a subsequent pipelined HTTP/1.1 request. This results in a desynchronized pooled connection, causing the next user of that connection to receive the response intended for the injected request. In reverse proxies, such as httputil.ReverseProxy, that utilize a shared Transport, this behavior can lead to cross-user response poisoning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-56866
GO-2026-6605

Affected Products

Go