Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Golang Go 安全漏洞
Vulnerability Description
Google Golang Go是美国谷歌(Google)公司的一种针对多处理器系统应用程序的编程进行了优化的编程语言。 Google Golang Go中的net/textproto/reader.go文件的net/http库存在安全漏洞,该漏洞源于程序没有正确的解析HTTP包头密钥。远程攻击者可利用该漏洞向服务器响应中注入HTTP头,绕过安全控制,实施缓存中毒攻击,修改请求或响应页面。
CVSS Information
N/A
Vulnerability Type
N/A