Description
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32977 | The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value. |
Ubuntu USN |
USN-7061-1 | Go vulnerabilities |
Ubuntu USN |
USN-7109-1 | Go vulnerabilities |
References
History
Tue, 17 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat stf
|
|
| CPEs | cpe:/a:redhat:stf:1.5::el8 | |
| Vendors & Products |
Redhat service Telemetry Framework
|
Redhat stf
|
Thu, 07 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Distributed Tracing
|
|
| CPEs | cpe:/a:redhat:openshift_distributed_tracing:2.9::el8 | |
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Mon, 19 Aug 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Subscriptions
Golang
Subscribe
Go
Subscribe
Redhat
Subscribe
Advanced Cluster Security
Subscribe
Cryostat
Subscribe
Enterprise Linux
Subscribe
Logging
Subscribe
Migration Toolkit Applications
Subscribe
Network Observ Optr
Subscribe
Openshift
Subscribe
Openshift Api Data Protection
Subscribe
Openshift Data Foundation
Subscribe
Openshift Distributed Tracing
Subscribe
Openshift Secondary Scheduler
Subscribe
Openshift Serverless
Subscribe
Openstack
Subscribe
Rhmt
Subscribe
Run Once Duration Override Operator
Subscribe
Satellite
Subscribe
Serverless
Subscribe
Stf
Subscribe
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-02-13T16:49:14.579Z
Reserved: 2023-04-05T19:36:35.043Z
Link: CVE-2023-29406
Updated: 2024-08-02T14:07:45.735Z
Status : Modified
Published: 2023-07-11T20:15:10.643
Modified: 2024-11-21T07:56:59.913
Link: CVE-2023-29406
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN