The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
History

Fri, 18 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-444
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 08 Apr 2025 21:45:00 +0000

Type Values Removed Values Added
References

Tue, 08 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Title Request smuggling due to acceptance of invalid chunked data in net/http
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2025-04-08T20:04:34.769Z

Updated: 2025-04-18T14:57:31.331Z

Reserved: 2025-01-08T19:11:42.834Z

Link: CVE-2025-22871

cve-icon Vulnrichment

Updated: 2025-04-08T21:03:21.913Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T20:15:20.183

Modified: 2025-04-18T15:15:57.923

Link: CVE-2025-22871

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-08T20:04:34Z

Links: CVE-2025-22871 - Bugzilla