The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Could somebody please add a value to the "Fixed in Version" field? @jwest ?
And FWIW, I believe the "Fixed in Version" value should be: Go 1.24.2 and Go 1.23.8
(In reply to Tom Sweeney from comment #6) > And FWIW, I believe the "Fixed in Version" value should be: Go 1.24.2 and Go > 1.23.8 Yes, that's right. These are the commits: https://github.com/golang/go/commit/ac1f5aa3d62efe21e65ce4dc30e6996d59acfbd0 https://github.com/golang/go/commit/15e01a2e43ecb8c7e15ff7e9d62fe3f10dcac931
Hey Tom. The "Fixed in Version" field is usually set by the engineering team based on which internal build contains the fix.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8477 https://access.redhat.com/errata/RHSA-2025:8477
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:8476 https://access.redhat.com/errata/RHSA-2025:8476
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:8478 https://access.redhat.com/errata/RHSA-2025:8478
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8539 https://access.redhat.com/errata/RHSA-2025:8539
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8601 https://access.redhat.com/errata/RHSA-2025:8601
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8633 https://access.redhat.com/errata/RHSA-2025:8633
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8632 https://access.redhat.com/errata/RHSA-2025:8632
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8634 https://access.redhat.com/errata/RHSA-2025:8634
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8665 https://access.redhat.com/errata/RHSA-2025:8665
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8666 https://access.redhat.com/errata/RHSA-2025:8666
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:8667 https://access.redhat.com/errata/RHSA-2025:8667
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:8685 https://access.redhat.com/errata/RHSA-2025:8685
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:8680 https://access.redhat.com/errata/RHSA-2025:8680
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:8682 https://access.redhat.com/errata/RHSA-2025:8682
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9 Via RHSA-2025:8691 https://access.redhat.com/errata/RHSA-2025:8691
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8689 https://access.redhat.com/errata/RHSA-2025:8689
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:8737 https://access.redhat.com/errata/RHSA-2025:8737
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:8916 https://access.redhat.com/errata/RHSA-2025:8916
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:8915 https://access.redhat.com/errata/RHSA-2025:8915
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:8918 https://access.redhat.com/errata/RHSA-2025:8918
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:8974 https://access.redhat.com/errata/RHSA-2025:8974
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:8975 https://access.redhat.com/errata/RHSA-2025:8975
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:8982 https://access.redhat.com/errata/RHSA-2025:8982
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:8983 https://access.redhat.com/errata/RHSA-2025:8983
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:8984 https://access.redhat.com/errata/RHSA-2025:8984
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9017 https://access.redhat.com/errata/RHSA-2025:9017
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9018 https://access.redhat.com/errata/RHSA-2025:9018
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9019 https://access.redhat.com/errata/RHSA-2025:9019
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9020 https://access.redhat.com/errata/RHSA-2025:9020
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Via RHSA-2025:9025 https://access.redhat.com/errata/RHSA-2025:9025
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9043 https://access.redhat.com/errata/RHSA-2025:9043
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9059 https://access.redhat.com/errata/RHSA-2025:9059
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9063 https://access.redhat.com/errata/RHSA-2025:9063
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9067 https://access.redhat.com/errata/RHSA-2025:9067
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9061 https://access.redhat.com/errata/RHSA-2025:9061
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9062 https://access.redhat.com/errata/RHSA-2025:9062
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9060 https://access.redhat.com/errata/RHSA-2025:9060
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9069 https://access.redhat.com/errata/RHSA-2025:9069
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9065 https://access.redhat.com/errata/RHSA-2025:9065
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9064 https://access.redhat.com/errata/RHSA-2025:9064
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9070 https://access.redhat.com/errata/RHSA-2025:9070
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9078 https://access.redhat.com/errata/RHSA-2025:9078
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9106 https://access.redhat.com/errata/RHSA-2025:9106
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9148 https://access.redhat.com/errata/RHSA-2025:9148
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9143 https://access.redhat.com/errata/RHSA-2025:9143
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9146 https://access.redhat.com/errata/RHSA-2025:9146
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9149 https://access.redhat.com/errata/RHSA-2025:9149
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9151 https://access.redhat.com/errata/RHSA-2025:9151
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9145 https://access.redhat.com/errata/RHSA-2025:9145
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9150 https://access.redhat.com/errata/RHSA-2025:9150
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9147 https://access.redhat.com/errata/RHSA-2025:9147
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9144 https://access.redhat.com/errata/RHSA-2025:9144
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9142 https://access.redhat.com/errata/RHSA-2025:9142
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9156 https://access.redhat.com/errata/RHSA-2025:9156
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9172 https://access.redhat.com/errata/RHSA-2025:9172
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9177 https://access.redhat.com/errata/RHSA-2025:9177
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:9200 https://access.redhat.com/errata/RHSA-2025:9200
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9199 https://access.redhat.com/errata/RHSA-2025:9199
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9205 https://access.redhat.com/errata/RHSA-2025:9205
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9207 https://access.redhat.com/errata/RHSA-2025:9207
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9206 https://access.redhat.com/errata/RHSA-2025:9206
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:9311 https://access.redhat.com/errata/RHSA-2025:9311
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9313 https://access.redhat.com/errata/RHSA-2025:9313
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:9319 https://access.redhat.com/errata/RHSA-2025:9319
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9317 https://access.redhat.com/errata/RHSA-2025:9317
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9312 https://access.redhat.com/errata/RHSA-2025:9312
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2025:9342 https://access.redhat.com/errata/RHSA-2025:9342
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:9278 https://access.redhat.com/errata/RHSA-2025:9278
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:9279 https://access.redhat.com/errata/RHSA-2025:9279
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:9623 https://access.redhat.com/errata/RHSA-2025:9623
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9635 https://access.redhat.com/errata/RHSA-2025:9635
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9634 https://access.redhat.com/errata/RHSA-2025:9634
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9639 https://access.redhat.com/errata/RHSA-2025:9639
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9637 https://access.redhat.com/errata/RHSA-2025:9637
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9638 https://access.redhat.com/errata/RHSA-2025:9638
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9642 https://access.redhat.com/errata/RHSA-2025:9642
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9640 https://access.redhat.com/errata/RHSA-2025:9640
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9641 https://access.redhat.com/errata/RHSA-2025:9641
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9715 https://access.redhat.com/errata/RHSA-2025:9715
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:9711 https://access.redhat.com/errata/RHSA-2025:9711
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9713 https://access.redhat.com/errata/RHSA-2025:9713
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9714 https://access.redhat.com/errata/RHSA-2025:9714
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:9712 https://access.redhat.com/errata/RHSA-2025:9712
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9756 https://access.redhat.com/errata/RHSA-2025:9756
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9844 https://access.redhat.com/errata/RHSA-2025:9844
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9845 https://access.redhat.com/errata/RHSA-2025:9845
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2025:9975 https://access.redhat.com/errata/RHSA-2025:9975
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 8 Red Hat Ansible Automation Platform 2.5 for RHEL 9 Via RHSA-2025:9986 https://access.redhat.com/errata/RHSA-2025:9986
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2025:10323 https://access.redhat.com/errata/RHSA-2025:10323
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:10291 https://access.redhat.com/errata/RHSA-2025:10291
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:10294 https://access.redhat.com/errata/RHSA-2025:10294
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:10295 https://access.redhat.com/errata/RHSA-2025:10295
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2025:10271 https://access.redhat.com/errata/RHSA-2025:10271