GO-2026-6566

Source
https://pkg.go.dev/vuln/GO-2026-6566
Import Source
https://vuln.go.dev/ID/GO-2026-6566.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2026-6566
Aliases
Published
2026-10-01T20:23:56Z
Modified
2026-10-01T20:45:14Z
Summary
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
Details

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio

Database specific
{
    "review_status":  "UNREVIEWED",
    "url":  "https://pkg.go.dev/vuln/GO-2026-6566"
}
References

Affected packages

Go / github.com/fabiolb/fabio

Package

Name
github.com/fabiolb/fabio
View open source insights on deps.dev
Purl
pkg:golang/github.com/fabiolb/fabio

Affected ranges

Type
SEMVER
Events
Introduced
1.6.6
Fixed
1.7.2

Ecosystem specific

{
    "imports":  [
        {
            "path":  "github.com/fabiolb/fabio",
            "symbols":  [
                "main",
                "newHTTPProxy"
            ]
        },
        {
            "path":  "github.com/fabiolb/fabio/proxy",
            "symbols":  [
                "HTTPProxy.ServeHTTP",
                "addHeaders"
            ]
        }
    ]
}

Database specific

source
"https://vuln.go.dev/ID/GO-2026-6566.json"