GO-2022-0761
Dashboard / Vulnerabilities / GO-2022-0761
Summary: Improper input validation in net/http and net/http/cgi
Details: An input validation flaw in the CGI components allows the HTTP_PROXY environment variable to be set by the incoming Proxy header, which changes where Go by default proxies all outbound HTTP requests. This environment variable is also used to set the outgoing proxy, enabling an attacker to insert a proxy into outgoing requests of a CGI program. Read more about "httpoxy" here: https://httpoxy.org.
References: https://go.dev/cl/25010, https://go.googlesource.com/go/+/b97df54c31d6c4cc2a28a3c83725366d52329223, https://go.dev/issue/16405, https://groups.google.com/g/golang-announce/c/7jZDOQ8f8tM/m/eWRWHnc8CgAJ
Affected packages
Package
Name: stdlib
Purl: pkg:golang/stdlib
Affected ranges
Type: SEMVER
Events:
