Description
When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Potential request smuggling
Action: Assess Impact
AI Analysis

Impact

The Go net/http server incorrectly continues to parse HTTP requests on a connection that has just returned a successful 2xx CONNECT response. A 2xx CONNECT turns the connection into a tunnel; the server should treat the stream as raw data, not as HTTP. The failure to switch modes allows an attacker to send data that an intermediate proxy interprets as part of the tunnel while the server still parses it as HTTP, creating a request smuggling condition. This weakness is a protocol parsing and synchronization fault (CWE‑151) coupled with improper state initialization (CWE‑665).

Affected Systems

The affected product is the Go standard library's net/http package. No specific version numbers are listed, but the issue is documented under GO-2026-6613. Read the release notes of your Go version and apply any patches that include this fix. If the Go runtime cannot be updated immediately, verify whether your deployment uses a vulnerable function.

Risk and Exploitability

Official CVSS, EPSS scores and KEV status are not available, and the vulnerability is not listed in the CISA KEV catalog, implying limited public exploitation data. The attack requires a malicious client or intermediary that can issue a CONNECT request to the target server and subsequently send data that the server will misinterpret as HTTP. If the attacker can influence the traffic that becomes a tunnel, they can potentially smuggle requests through intermediaries, leading to unauthorized downstream request framing or even privilege escalation if the server reacts to injected internal requests. The likelihood of exploitation is currently unknown but could rise if attackers prioritize protocol desynchronization techniques.

Generated by OpenCVE AI on October 9, 2026 at 00:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go release that contains the GO-2026-6613 fix.
  • If upgrading is not possible, block or reject HTTP/1 CONNECT methods at a perimeter firewall, reverse proxy, or application firewall.
  • Ensure that any handler that sends a 2xx CONNECT response immediately hijacks or closes the underlying connection instead of continuing to parse HTTP traffic—this may involve calling ResponseWriter.Hijack and then exiting.
  • As an additional precaution, verify that intermediate proxies enforce correct handling of CONNECT responses, treating them strictly as tunnel initiations.

Generated by OpenCVE AI on October 9, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-151
CWE-665

Fri, 09 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library net/http
Vendors & Products Go Standard Library
Go Standard Library net/http

Fri, 09 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-444
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.
Title HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http
References

Subscriptions

Go Standard Library Net/http
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:59.976Z

Reserved: 2026-09-21T16:43:04.757Z

Link: CVE-2026-94439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:04.760

Modified: 2026-10-08T23:17:04.760

Link: CVE-2026-94439

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-08T22:53:59Z

Links: CVE-2026-94439 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:00:14Z

Weaknesses
  • CWE-151

    Improper Neutralization of Comment Delimiters

  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

  • CWE-665

    Improper Initialization