CVE-2015-5739

critical
Published 2017-10-18 · Modified 2024-05-20
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Request smuggling due to improper header parsing in net/http

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=1250352

OS impact

OSVersionStatusFixed in
redhat rhel7.0affected
fedora fedora21affected
fedora fedora22affected

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib<1.4.31.4.3

Application impact

VendorProductVersionsFixed
golanggo{"endIncluding":"1.4.2"}

References

CWEs

CWE-444

Verify integrity in audit chain (admin only). AS-IS.