HTTP/1 CONNECT Request Vulnerability in Go's HTTP Transport by Google
CVE-2026-56866

Currently unrated

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-56866?

This vulnerability occurs when the Go HTTP Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body. The body is written directly to the connection without proper framing after the headers. In cases where the server responds with a non-2xx keep-alive status, the connection is returned to the idle pool. Since CONNECT requests should not include a request body, the server may misinterpret the trailing body bytes as a subsequent HTTP/1.1 pipelined request. This desynchronization can lead to response poisoning, especially in environments using reverse proxies that forward CONNECT requests through a shared Transport, resulting in unintended interactions between different users.

Affected Version(s)

net/http 0 < 1.26.9

net/http 1.27.0-0 < 1.27.2

net/http/httputil 0 < 1.26.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xclow3n (Rajat Raghav)
.