Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4073
HistoryMay 02, 2017 - 7:41 a.m.

Request Smuggling

2017-05-0207:41:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.013 Low

EPSS

Percentile

85.9%

net/http in github.com/golang/go is vulnerable to request smuggling. This can be done because it does not correctly comply with RFC 7230. If a request is sent with both a Transfer-Encoding header and a Content-Length header, this was being ignored.