golang: malformed hosts in URLs leads to authorization bypass
Published Aug 13, 2019
9.8
CRITICALCVSS 3.0
EPSS 8.36%
Description
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com.
Affected products
No data.
No data.
Red Hat Developer Tools
go-toolset-1.12-0:1.12.8-2.el7
Fixed · RHEA-2019:4179
Red Hat Developer Tools
go-toolset-1.12-golang-0:1.12.8-2.el7
Fixed · RHEA-2019:4179
Red Hat Enterprise Linux 8
go-toolset:rhel8-8010020190829001136.ccff3eb7
Fixed · RHSA-2019:3433
Red Hat Ceph Storage 2
golang
Will not fix
Red Hat Ceph Storage 3
golang
Will not fix
Red Hat Enterprise Linux 7
golang
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
golang
Out of support scope
Red Hat Storage 3
golang
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Tools | go-toolset-1.12-0:1.12.8-2.el7 | Fixed | RHEA-2019:4179 |
| Red Hat Developer Tools | go-toolset-1.12-golang-0:1.12.8-2.el7 | Fixed | RHEA-2019:4179 |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8-8010020190829001136.ccff3eb7 | Fixed | RHSA-2019:3433 |
| Red Hat Ceph Storage 2 | golang | Will not fix | n/a |
| Red Hat Ceph Storage 3 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | golang | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | golang | Out of support scope | n/a |
| Red Hat Storage 3 | golang | Affected | n/a |
stdlib
Go
Introduced 0 Fixed 1.11.13stdlib
Go
Introduced 1.12.0-0 Fixed 1.12.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | stdlib | 0 | 1.11.13 |
| Go | stdlib | 1.12.0-0 | 1.12.8 |
Remediation
Red Hat mitigation
This flaw has no mitigation for any affected golang package versions.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (27 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 8.36% (0.08359) | 94.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.36% (0.08359) | 94.23th | v5 (v2026.06.15) |
| Nov 21, 2025 | 2.58% (0.02582) | 85.06th | v4 (v2025.03.14) |
| Nov 18, 2025 | 9.55% (0.09550) | 92.03th | v4 (v2025.03.14) |
| Sep 1, 2025 | 1.78% (0.01779) | 82.05th | v4 (v2025.03.14) |
| Aug 9, 2025 | 3.43% (0.03432) | 87.03th | v4 (v2025.03.14) |
| Aug 5, 2025 | 4.74% (0.04735) | 89.00th | v4 (v2025.03.14) |
| Aug 1, 2025 | 2.73% (0.02727) | 85.46th | v4 (v2025.03.14) |
| Jul 5, 2025 | 4.74% (0.04735) | 88.92th | v4 (v2025.03.14) |
| Jul 1, 2025 | 2.73% (0.02727) | 85.38th | v4 (v2025.03.14) |
| Jun 6, 2025 | 4.74% (0.04735) | 88.86th | v4 (v2025.03.14) |
| Jun 1, 2025 | 2.73% (0.02727) | 85.28th | v4 (v2025.03.14) |
| May 11, 2025 | 4.74% (0.04735) | 88.80th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.23% (0.01228) | 77.77th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.09% (0.01094) | 84.16th | v3 (v2023.03.01) |
| Dec 7, 2023 | 3.74% (0.03744) | 90.83th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.71% (0.02712) | 89.38th | v3 (v2023.03.01) |
| Jul 20, 2023 | 2.53% (0.02534) | 88.71th | v3 (v2023.03.01) |
| Jul 4, 2023 | 2.23% (0.02227) | 87.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.65% (0.01646) | 85.58th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 24.56% (0.24563) | 95.26th | v2 (v2022.01.01) |
| Feb 3, 2022 | 11.74% (0.11741) | 88.45th | v1 |
| Jan 6, 2022 | 11.74% (0.11741) | 88.31th | v1 |
| Sep 1, 2021 | 2.88% (0.02880) | 80.71th | v1 |
| Apr 14, 2021 | 2.88% (0.02880) | 0.00th | v1 |
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/errata/RHSA-2019:3433 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-14809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1743129 Issue Tracking
- https://github.com/golang/go/commit/61bb56ad63992a3199acc55b2537c8355ef887b6
- https://github.com/golang/go/issues/29098 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://groups.google.com/forum/#%21topic/golang-announce/0uuMm1BwpHE x_refsource_MISC
- https://groups.google.com/forum/#%21topic/golang-announce/65QixT3tcmg x_refsource_CONFIRM
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQ/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-14809
- https://seclists.org/bugtraq/2019/Aug/31 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14809
- https://www.debian.org/security/2019/dsa-4503 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.