Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22871

Опубликовано: 08 апр. 2025
Источник: debian
EPSS Низкий

Описание

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.24fixed1.24.2-1package
golang-1.23fixed1.23.8-1package
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk/m/cs_6qIK5BAAJ

  • https://github.com/golang/go/issues/71988

  • Fixed by: https://github.com/golang/go/commit/ac1f5aa3d62efe21e65ce4dc30e6996d59acfbd0 (go1.24.2)

  • Fixed by: https://github.com/golang/go/commit/15e01a2e43ecb8c7e15ff7e9d62fe3f10dcac931 (go1.23.8)

EPSS

Процентиль: 4%
0.00023
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

CVSS3: 5.4
redhat
2 месяца назад

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

CVSS3: 9.1
nvd
2 месяца назад

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

CVSS3: 9.1
msrc
2 месяца назад

Описание отсутствует

suse-cvrf
2 месяца назад

Security update for go1.24

EPSS

Процентиль: 4%
0.00023
Низкий