The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.23.8-1", "binary_name": "golang-1.23" }, { "binary_version": "1.23.8-1", "binary_name": "golang-1.23-doc" }, { "binary_version": "1.23.8-1", "binary_name": "golang-1.23-go" }, { "binary_version": "1.23.8-1", "binary_name": "golang-1.23-src" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.24.2-1", "binary_name": "golang-1.24" }, { "binary_version": "1.24.2-1", "binary_name": "golang-1.24-doc" }, { "binary_version": "1.24.2-1", "binary_name": "golang-1.24-go" }, { "binary_version": "1.24.2-1", "binary_name": "golang-1.24-go-dbgsym" }, { "binary_version": "1.24.2-1", "binary_name": "golang-1.24-src" } ] }