Impact
The Go net/http server incorrectly continues to parse HTTP requests on a connection that has just returned a successful 2xx CONNECT response. A 2xx CONNECT turns the connection into a tunnel; the server should treat the stream as raw data, not as HTTP. The failure to switch modes allows an attacker to send data that an intermediate proxy interprets as part of the tunnel while the server still parses it as HTTP, creating a request smuggling condition. This weakness is a protocol parsing and synchronization fault (CWE‑151) coupled with improper state initialization (CWE‑665).
Affected Systems
The affected product is the Go standard library's net/http package. No specific version numbers are listed, but the issue is documented under GO-2026-6613. Read the release notes of your Go version and apply any patches that include this fix. If the Go runtime cannot be updated immediately, verify whether your deployment uses a vulnerable function.
Risk and Exploitability
Official CVSS, EPSS scores and KEV status are not available, and the vulnerability is not listed in the CISA KEV catalog, implying limited public exploitation data. The attack requires a malicious client or intermediary that can issue a CONNECT request to the target server and subsequently send data that the server will misinterpret as HTTP. If the attacker can influence the traffic that becomes a tunnel, they can potentially smuggle requests through intermediaries, leading to unauthorized downstream request framing or even privilege escalation if the server reacts to injected internal requests. The likelihood of exploitation is currently unknown but could rise if attackers prioritize protocol desynchronization techniques.
OpenCVE Enrichment