Back

HIGH

golang: HTTP/1.1 headers with a space before the colon leads to filter bypass or request smuggling

Published Sep 30, 2019

Description

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

Affected products

Remediation

Red Hat statement

* This issue affects the versions of golang as shipped with Red Hat Enterprise Linux 7, however it was deprecated in Red Hat Enterprise Linux 7.6 and it does not receive updates anymore. Developers are encouraged to use the Go Toolset instead, which is available through the Red Hat Developer program. See https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/chap-red_hat_enterprise_linux-7.6_release_notes-other_deprecated_functionality#idm140555585405248. * The version of golang provided in Red Hat Gluster Storage 3, Red Hat Ceph Storage 2 and Red Hat Ceph Storage 3 allows filter bypasses or request smuggling and contains the vulnerable code hence affected by this vulnerability. * In OpenShift Container Platform, all packages and container images built with a vulnerable version of Go and use the net/http package are affected by this flaw.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 30, 2019
Updated Aug 5, 2024
Reserved Sep 12, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 25, 2019
ENISA EUVD
Assigner mitre
Published Sep 30, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-7075