Go standard library net/http
7 known vulnerabilities in Go standard library net/http, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56853 CVSS 7.5 high When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2…
- CVE-2026-39821 CVSS 9.6 critical The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example…
- CVE-2026-33814 CVSS 7.5 high When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a…
- CVE-2025-58186 CVSS 5.3 medium Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of…
- CVE-2025-4673 CVSS 6.8 medium Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
- CVE-2025-22870 CVSS 4.4 medium Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY…
- CVE-2024-45336 CVSS 6.1 medium The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an…