The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.
https://security.netapp.com/advisory/ntap-20230814-0002/
https://security.gentoo.org/glsa/202311-09
https://pkg.go.dev/vuln/GO-2023-1878
Published: 2023-07-11
Updated: 2026-06-17
Named Vulnerability: GO-2023-1878Named Vulnerability: GHSA-f8f7-69v5-w4vx
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N
Severity: High
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Severity: Medium
EPSS: 0.01471