CVE-2015-5741: Golang Go
Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
Affected products
- Golang Go: before 1.4.3 (fixed in 1.4.3)
- Red Hat Enterprise Linux: version 7.0 only
- Red Hat Openstack: version 7.0 only; version 8 only
Published 2020-02-08. Last modified 2026-06-17.