HTTP/1 CONNECT Request Vulnerability in Go's HTTP Transport by Google
CVE-2026-56866
What is CVE-2026-56866?
This vulnerability occurs when the Go HTTP Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body. The body is written directly to the connection without proper framing after the headers. In cases where the server responds with a non-2xx keep-alive status, the connection is returned to the idle pool. Since CONNECT requests should not include a request body, the server may misinterpret the trailing body bytes as a subsequent HTTP/1.1 pipelined request. This desynchronization can lead to response poisoning, especially in environments using reverse proxies that forward CONNECT requests through a shared Transport, resulting in unintended interactions between different users.
Affected Version(s)
net/http 0 < 1.26.9
net/http 1.27.0-0 < 1.27.2
net/http/httputil 0 < 1.26.9
