Loading HuntDB...

GHSA-5hv8-7f46-fxf6

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

Related CVEs

Key Information

GHSA ID
GHSA-5hv8-7f46-fxf6
Published
August 11, 2022 12:00 AM
Last Modified
August 17, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 18, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.