当 HTTP 服务器处理器向 HTTP/1 CONNECT 请求发送 2xx 响应且未接管(hijack)连接就返回时,服务器会不当继续从该连接读取并处理请求。由于对 HTTP/1 CONNECT 请求的 2xx 响应会将该连接转换为隧道(tunnel),因此服务器不应再将该连接视为包含 HTTP 数据。这种错误行为的影响主要限于潜在的请求走私(request smuggling)问题,其中中间代理将连接上的数据视为已隧穿(tunneled)内容,而服务器却将其当作普通 HTTP 请求来处理。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go standard library | net/http | 0 ~ 1.26.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94440 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart | |
| CVE-2026-94448 | Reset context tracking on consecutive template expressions in html/template | |
| CVE-2026-56857 | Root.Mkdir(All) can follow junctions out of the root on Windows in os | |
| CVE-2026-56866 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http | |
| CVE-2026-78659 | HTTP/2 server memory exhaustion due to Trailer headers in net/http | |
| CVE-2026-78660 | HTTP/2 transport accepts malformed framing-related headers in net/http | |
| CVE-2026-78663 | Double flow control refund on HTTP/2 server streams in net/http | |
| CVE-2026-78667 | Lack of limit on size of parsed Range headers in net/http | |
| CVE-2026-78669 | Excessive CPU consumption from repeated initial window changes in net/http | |
| CVE-2026-97032 | HTTP/2 server crash due to HPACK encoder race in net/http | |
| CVE-2026-97030 | Recognize yield as regexp preceder keyword in html/template | |
| CVE-2026-97031 | Reject malformed ECH outer extension references in crypto/tls |
No comments yet