Project Subscriptions
| Vendors | Products |
|---|---|
|
Redhat
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11855 | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext. |
Github GHSA |
GHSA-g9pc-8g42-g6vq | RoadRunner is at risk of HTTP Request/Response Smuggling through vulnerable dependency |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.12::el8 |
Wed, 09 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.17::el8 cpe:/a:redhat:openshift:4.17::el9 |
Fri, 04 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat cryostat
|
|
| CPEs | cpe:/a:redhat:cryostat:4::el9 | |
| Vendors & Products |
Redhat cryostat
|
Tue, 01 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.5::el8 cpe:/a:redhat:ansible_automation_platform:2.5::el9 |
Tue, 01 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat ansible Automation Platform
|
|
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.4::el8 cpe:/a:redhat:ansible_automation_platform:2.4::el9 |
|
| Vendors & Products |
Redhat ansible Automation Platform
|
Wed, 25 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.19::el8 cpe:/a:redhat:openshift:4.19::el9 |
|
| Vendors & Products |
Redhat openshift
|
Mon, 23 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhmt
|
|
| CPEs | cpe:/a:redhat:rhel_aus:8.2 cpe:/a:redhat:rhmt:1.8::el8 |
|
| Vendors & Products |
Redhat rhmt
|
Tue, 17 Jun 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhel_aus:8.4 |
Mon, 16 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Ai
Redhat rhel Aus |
|
| CPEs | cpe:/a:redhat:openshift_ai:2.21::el9 cpe:/a:redhat:rhel_aus:8.6 cpe:/a:redhat:rhel_e4s:8.6 cpe:/a:redhat:rhel_tus:8.6 |
|
| Vendors & Products |
Redhat openshift Ai
Redhat rhel Aus |
Thu, 12 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:rhel_e4s:9.0 |
Tue, 10 Jun 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
Redhat openshift Serverless Redhat rhel E4s Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:acm:2.13::el9 cpe:/a:redhat:openshift_serverless:1.36::el8 cpe:/a:redhat:rhel_e4s:8.8 cpe:/a:redhat:rhel_e4s:9.2 cpe:/a:redhat:rhel_tus:8.8 |
|
| Vendors & Products |
Redhat acm
Redhat openshift Serverless Redhat rhel E4s Redhat rhel Tus |
Fri, 06 Jun 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat enterprise Linux
Redhat rhel Eus |
|
| CPEs | cpe:/a:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:rhel_eus:9.4 cpe:/o:redhat:enterprise_linux:10.0 |
|
| Vendors & Products |
Redhat enterprise Linux
Redhat rhel Eus |
Sat, 31 May 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat service Mesh |
|
| CPEs | cpe:/a:redhat:service_mesh:3.0::el9 | |
| Vendors & Products |
Redhat
Redhat service Mesh |
Fri, 18 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 09 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 08 Apr 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 08 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext. | |
| Title | Request smuggling due to acceptance of invalid chunked data in net/http | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-04-18T14:57:31.331Z
Reserved: 2025-01-08T19:11:42.834Z
Link: CVE-2025-22871
Updated: 2025-04-08T21:03:21.913Z
Status : Awaiting Analysis
Published: 2025-04-08T20:15:20.183
Modified: 2025-04-18T15:15:57.923
Link: CVE-2025-22871
OpenCVE Enrichment
No data.
EUVD
Github GHSA