CVE Published: 11/07/2023 |
CVE Updated: 07/11/2024 |
CVE Year: 2023 Source: Go |
Vendor: Go standard library |
Product: net/http Status : PUBLISHED
CVE-2023-29406 Description
The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.