CVE-2015-5739

EPSS 11.9%

Request smuggling due to improper header parsing in net/http

Published: 1/5/2022Modified: 5/20/2024

Description

HTTP headers were not properly parsed, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.

Affected packages (1)

References (11)