Impact
When a client sends a CONNECT request with a non‑empty body, the Go http.Transport writes the body directly to the connection after the headers. If the server rejects the CONNECT with a non‑2xx keep‑alive response, the transport returns that connection to the idle pool. Because CONNECT requests have no body, the server can interpret the trailing body bytes as a new pipelined HTTP request. The reused connection may then deliver the attacker‑controlled response to another client, resulting in cross‑user response poisoning. This flaw exposes internal application data to unintended parties and can lead to unauthorized disclosure. The weakness involves improper handling of persistent connections and leftover data in the connection stream.
Affected Systems
The vulnerability affects the Go standard library packages net/http and net/http/httputil used in any Go application that employs an http.Transport or ReverseProxy. No specific version range is defined in the advisory, so any use of these packages prior to the fix is potentially susceptible.
Risk and Exploitability
The CVSS score and EPSS are not published, and the issue is not listed in the CISA KEV catalog. The exploitation requires an attacker to control a client that uses a shared Transport to send a CONNECT request with a body to a server that rejects the request. The attacker then injects an HTTP request into the body that the server processes as a new request, leaving the idle connection desynchronised. Depending on the target application and the data exposed by the poisoned response, the impact could range from information disclosure to functional manipulation of downstream requests. In environments where Go applications share Transport instances across users, the risk is amplified, although the lack of publicly available severity metrics suggests a moderate to high potential risk pending further assessment.
OpenCVE Enrichment