PT-2026-108309 · Google · Go
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Go (affected versions not specified)
Description
When
http.Transport sends an HTTP/1 CONNECT request containing a non-empty Request.Body, the body is written directly to the connection without framing following the request headers. If the server responds to the CONNECT request with a non-2xx keep-alive response, the connection is returned to the idle pool. Since CONNECT requests are not expected to have a request body, the server may treat the remaining body bytes as a subsequent pipelined HTTP/1.1 request. This results in a desynchronized pooled connection, causing the next user of that connection to receive the response intended for the injected request. In reverse proxies, such as httputil.ReverseProxy, that utilize a shared Transport, this behavior can lead to cross-user response poisoning.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Go