Inconsistent interpretation of HTTP requests in Go programming language - CVE-2019-16276
Published: September 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to Go programming language accepts and normalizes HTTP requests with malformed HTTP/1.1 headers containing a space before the colon. A remote attacker can use a malformed request to bypass configured filtration and gain access to presumably restricted functionality.
Affected software
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Red Hat Developer Tools
Sensor Proxy
golang-1.11 (Debian package)
go (Alpine package)
golang
Red Hat OpenShift Container Platform
How to mitigate CVE-2019-16276
Sensor Proxy - update to 1.0.12
golang-1.11 (Debian package) - update to 1.11.6-1+deb10u2
go (Alpine package) - update to 1.13.1-r0
Red Hat OpenShift Container Platform - update to 4.2.21
golang - addressed in versions 1.11.13-2.fc29, 1.12.10-1.fc30, 1.13.1-1.el6, 1.13.1-1.el7, 1.13.1-1.fc31
External References
Related Security Bulletins
- HTTP request smuggling in Go programming language
- Debian update for golang-1.11
- OpenSUSE Linux update for go1.12
- OpenSUSE Linux update for go1.12
- Amazon Linux AMI update for golang
- Red Hat update for go-toolset-1.12-golang
- Amazon Linux AMI update for golang
- Red Hat update for go-toolset:rhel8
- OpenShift Container Platform update for golang
- Inconsistent interpretation of HTTP requests in go (Alpine package)
- Fedora 30 update for golang
- Fedora 31 update for golang
- Fedora 29 update for golang
- Fedora EPEL 7 update for golang
- Fedora EPEL 6 update for golang
- Tenable Sensor Proxy update for third-party components