VDB

RHSA-2022%3A6187

RHSA-2022%3A6187 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in golang. The HTTP/1 client accepted invalid Transfer-Encoding headers indicating "chunked" encoding. This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red Hatworkload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64, workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64, workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64
Red Hatworkload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64
golanggo
golangGo
Red Hatworkload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8*, *, *
Red Hatworkload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8*, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64, workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64

Timeline

  • Aug 25, 2022 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Jun 19, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›