Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6610"
}{
"imports": [
{
"path": "net/http",
"symbols": [
"Client.CloseIdleConnections",
"Client.Do",
"Client.Get",
"Client.Head",
"Client.Post",
"Client.PostForm",
"ClientConn.Close",
"ClientConn.RoundTrip",
"Get",
"Head",
"Post",
"PostForm",
"Transport.CloseIdleConnections",
"Transport.NewClientConn",
"Transport.RoundTrip",
"http1ClientConn.Close",
"http1ClientConn.RoundTrip",
"http2Transport.NewClientConn",
"http2Transport.RoundTrip",
"http2Transport.RoundTripOpt",
"http2clientConnPool.GetClientConn",
"http2clientConnReadLoop.handleResponse",
"http2noDialClientConnPool.GetClientConn",
"http2noDialH2RoundTripper.NewClientConn",
"http2noDialH2RoundTripper.RoundTrip",
"http2unencryptedTransport.RoundTrip"
]
}
]
}
{
"imports": [
{
"path": "golang.org/x/net/http2",
"symbols": [
"Transport.NewClientConn",
"Transport.RoundTrip",
"Transport.RoundTripOpt",
"clientConnPool.GetClientConn",
"clientConnReadLoop.handleResponse",
"noDialClientConnPool.GetClientConn",
"noDialH2RoundTripper.NewClientConn",
"noDialH2RoundTripper.RoundTrip",
"unencryptedTransport.RoundTrip"
]
}
]
}