CVE-2025-22871: Go Standard Library Net/http/internal
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Affected products
- Go Standard Library Net/http/internal: before 1.23.8 (fixed in 1.23.8); from 1.24.0-0, before 1.24.2 (fixed in 1.24.2)
- Siemens Sentron 7kt PAC1261 Data Manager: before V2.1.0 (fixed in V2.1.0)
Published 2025-04-08. Last modified 2026-06-17.