Impact
This vulnerability resides in the Go HTTP/2 implementation. The framework allows malformed framing‑related headers because they cannot corrupt the HTTP/2 framing itself. When acting as a reverse proxy, the implementation forwards such headers to an HTTP/1 client. If that downstream client accepts the headers without strict validation, an attacker can craft responses that are split or merged in the HTTP/1 stream, leading to response smuggling. The flaw results from insufficient input validation (CWE‑20). The attacker can inject arbitrary data into the response, exposing confidential information or manipulating application behavior. The likely attack vector is an attacker sending a malicious HTTP/2 request with malformed framing‑related headers to a reverse proxy that forwards to an HTTP/1 client.
Affected Systems
The affected components are Go’s net/http, net/http/internal/http2, and golang.org/x/net/http2 packages. All Go releases compiled with these packages prior to the referenced fixes are vulnerable. No explicit version list is provided in the advisory.
Risk and Exploitability
The issue can be exploited only when an attacker can inject malformed headers into an HTTP/2 request that is then proxied to an HTTP/1 client and that client is permissive to header parsing. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the exploit requires a specific proxy configuration and a vulnerable downstream client, so the likelihood of exploitation is low to moderate; however, the impact of a successful smuggle can be significant.
OpenCVE Enrichment