VDB
GO-2023-1495
GO-2023-1495
PUBLISHED
Request smuggling due to improper request handling in golang.org/x/net/http2/h2c
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| golang.org | x/net | 0.0.0-20220524220425-1d687d428aca, 0.0.0-20220524220425 |
Timeline
- Jan 13, 2023 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://go.dev/issue/56352 report
- https://go.dev/cl/447396 patch