Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21580
HistorySep 27, 2019 - 3:44 a.m.

HTTP Request Smuggling

2019-09-2703:44:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.012

Percentile

85.7%

github.com/golang/go is vulnerable to HTTP request smuggling. The vulnerability exists as invalid HTTP/1.1 headers were accepted and normalized with a space before the colon, allowing a reverse proxy to interpret the headers differently.

References