CVE-2024-45258

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-45258
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45258.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45258
Aliases
Published
2024-08-25T22:15:05Z
Modified
2024-10-07T23:30:57Z
Summary
[none]
Details

The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.

References

Affected packages

Git / github.com/imroc/req

Affected ranges

Type
GIT
Repo
https://github.com/imroc/req
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed