Cross-Domain Redirect Vulnerability in Go's HTTP Client
CVE-2024-45336
Key Information:
- Vendor
Go Standard Library
- Status
- Vendor
- CVE Published:
- 28 January 2025
Badges
What is CVE-2024-45336?
A vulnerability in the Go HTTP client allows sensitive headers to be dropped when following cross-domain redirects. Specifically, when the HTTP client is redirected from one domain to another, it does not send sensitive headers, such as the Authorization header, to the second domain. However, if the client follows a sequence of redirects that remain within the same domain, these sensitive headers are incorrectly restored and sent to subsequent requests within that domain. This behavior can lead to unintended exposure of sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
net/http 0 < 1.22.11
net/http 1.23.0-0 < 1.23.5
net/http 1.24.0-0 < 1.24.0-rc.2
News Articles
References
CVSS V3.1
Timeline
Vulnerability published
- ๐ฐ
First article discovered by KrakenD
Vulnerability Reserved
