CVE-2019-9741: Debian Linux

Medium severity, CVSS 6.1. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 29 only
  • Golang Go: version 1.11.5 only
  • Red Hat Developer Tools: version 1.0 only
  • Red Hat Enterprise Linux: version 8.0 only

Published 2019-03-13. Last modified 2026-06-17.