CVE-2015-5741: Golang Go

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.

Affected products

  • Golang Go: before 1.4.3 (fixed in 1.4.3)
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Openstack: version 7.0 only; version 8 only

Published 2020-02-08. Last modified 2026-06-17.