CVE Database
/

CVE-2025-22871

Back to search

CVE-2025-22871

Published: Apr 8, 2025

Modified: May 12, 2026

PUBLISHED

Description

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

VendorProductVersions

Go standard library

net/http/internal

affected
0 - < 1.23.8
affected
1.24.0-0 - < 1.24.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-22871 - Security Vulnerability | QwikSec