CVE-2025-22871

Source
https://cve.org/CVERecord?id=CVE-2025-22871
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22871.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-22871
Aliases
Downstream
AZL (5)
BELL (1)
CGA (2997)
CLEANSTART (32)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (38)
OESA (3)
openSUSE (7)
RHBA (1)
RHSA (97)
RLSA (29)
SUSE (6)
UBUNTU (1)
Related
Published
2025-04-08T20:15:20Z
Modified
2026-07-29T18:29:58Z
Summary
[none]
Details

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

References

Affected packages