CVE-2023-29406: Golang Go

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

Affected products

  • Golang Go: before 1.19.11 (fixed in 1.19.11); from 1.20.0, before 1.20.6 (fixed in 1.20.6)

Published 2023-07-11. Last modified 2026-06-17.