VDB

RHSA-2020%3A0652

RHSA-2020%3A0652 PUBLISHED CVSS 6.5 MEDIUM

It was discovered that net/http (through net/textproto) in golang does not correctly interpret HTTP requests where an HTTP header contains spaces before the colon. This could be abused by an attacker to smuggle HTTP requests when a proxy or a firewall is placed behind a server implemented in Go or to filter bypasses depending on the specific network configuration.

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-installer@sha256:c7d9b92f07e455467d99a90402026873b11716073820365ddf2408419e1aeff4_amd64 as a component of Red Hat OpenShift Container Platform 4.2*
Red Hatopenshift4/ose-installer-artifacts@sha256:59830f36fe5430560e979f4628c47f18e2b3a4dcf7d6480ea1cece126a147bf5_amd64 as a component of Red Hat OpenShift Container Platform 4.2openshift4/ose-installer-artifacts@sha256:59830f36fe5430560e979f4628c47f18e2b3a4dcf7d6480ea1cece126a147bf5_amd64
Red Hatopenshift4/ose-installer@sha256:10542c71ffb400b3fb5eb760ff89cf214f43f40782352e7ecfa4cbf26566704a_s390x as a component of Red Hat OpenShift Container Platform 4.2openshift4/ose-installer@sha256:10542c71ffb400b3fb5eb760ff89cf214f43f40782352e7ecfa4cbf26566704a_s390x
Red Hatopenshift4/ose-installer-artifacts@sha256:41c8e72f58cdff8d65219d0da45ef381cc7b6db50e702edc9ee9cd4b662db05b_s390x as a component of Red Hat OpenShift Container Platform 4.2openshift4/ose-installer-artifacts@sha256:41c8e72f58cdff8d65219d0da45ef381cc7b6db50e702edc9ee9cd4b662db05b_s390x

Timeline

  • Mar 5, 2020 CVE Published
  • Feb 26, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›