Aller au contenu

Fiche vulnérabilité

CVE-2022-41721 : faille élevée golang h2c (CVSS 7.5)

Description

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
13 janv. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • golang h2c

Références

Rechercher une autre vulnérabilité dans la base CVE