CVE-2025-22871

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Configurations

No configuration.

History

No history.

Information

Published : 2025-04-08 20:15

Updated : 2026-06-17 08:50


NVD link : CVE-2025-22871

Mitre link : CVE-2025-22871

CVE.ORG link : CVE-2025-22871


JSON object : View

Products Affected

No product.

CWE

No CWE.