Description

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

INFO

Published Date :

2025-04-08T20:04:34.769Z

Last Modified :

2025-04-18T14:57:31.331Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2025-22871 vulnerability.

Vendors Products
Redhat
  • Acm
  • Ansible Automation Platform
  • Cryostat
  • Enterprise Linux
  • Openshift
  • Openshift Ai
  • Openshift Serverless
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Tus
  • Rhmt
  • Service Mesh

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact