Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29406


The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.


Published

2023-07-11T20:15:10.643

Last Modified

2024-11-21T07:56:59.913

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-436

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application golang go < 1.19.11 Yes
Application golang go < 1.20.6 Yes

References