PT-2026-108311 · Go+2 · Golang.Org/X/Net+4
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The HTTP/2 implementation is lax regarding malformed framing-related headers. When acting as a reverse proxy, the system may forward responses containing these malformed headers to an HTTP/1 client. If the client does not strictly validate these headers, it can lead to response smuggling, a technique where an attacker interferes with the way a proxy and a backend server interpret the sequence of HTTP responses.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Golang.Org/X/Net
Golang.Org/X/Net/Http2
Net/Http
Net/Http/Internal/Http2
Stdlib