PT-2026-108315 · Go Standard Library+1 · Net/Http+1

·

CVE-2026-94439

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An HTTP server handler improperly continues to read and serve requests from a connection after sending a 2xx response to an HTTP/1 CONNECT request without hijacking the connection. Because a 2xx response to an HTTP/1 CONNECT is intended to convert the connection into a tunnel, the server should stop treating the connection as HTTP. This behavior can lead to request smuggling, a technique where an attacker interferes with the way a website processes sequences of HTTP requests, occurring when an intermediate proxy views the connection data as tunneled while the server interprets it as HTTP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-94439
GO-2026-6613

Affected Products

Net/Http
Stdlib