Request Smuggling Vulnerability in Go HTTP Server
CVE-2026-94439
Currently unrated
What is CVE-2026-94439?
This vulnerability occurs when a Go HTTP server improperly handles HTTP/1 CONNECT requests. Specifically, if the server responds with a 2xx status code without hijacking the connection, it erroneously keeps the connection open for further requests. This behavior leads to a scenario where request smuggling can occur, as an intermediate proxy may regard the data on the connection as being tunneled, while the server processes it as standard HTTP data. This discrepancy can potentially be exploited by attackers to manipulate HTTP requests and responses.
Affected Version(s)
net/http 0 < 1.26.9
net/http 1.27.0-0 < 1.27.2
