Back to search
CVE-2022-1705
Published: Aug 9, 2022
Modified: Mar 6, 2026
PUBLISHED
Description
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
| Vendor | Product | Versions |
|---|---|---|
Go standard library | net/http | affected 0 - < 1.17.12affected 1.18.0-0 - < 1.18.4 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now