CVE-2020-15586
MEDIUM5.9EPSS 0.61%golang-1.11 - security update
Published: 2/17/2022Modified: 4/28/2026
Description
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
Affected packages (6)
- Bitnami/golangfrom 0, < 1.13.13, >= 1.14.0, < 1.14.5
- Debian/golang-1.11from 0, < 1.11.6-1+deb10u4
- Debian/golang-1.15from 0, < 1.15~rc1-1
- Debian/golang-1.7from 0, < 1.7.4-2+deb9u2
- Debian/golang-1.8from 0, < 1.8.1-1+deb9u2
- Go/stdlibfrom 0, < 1.13.13, >= 1.14.0-0, < 1.14.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (20)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-15586
- PATCHhttps://go.dev/cl/242598
- PATCHhttps://go.googlesource.com/go/+/fa98f46741f818913a8c11b877520a548715131f
- REPORThttps://go.dev/issue/34902
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00077.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00082.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00029.html
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00030.html
- WEBhttps://groups.google.com/forum/#%21topic/golang-announce/f2c5bqrGH_g
- WEBhttps://groups.google.com/forum/#%21topic/golang-announce/XZNfaiwgt2w
- WEBhttps://groups.google.com/g/golang-announce/c/XZNfaiwgt2w
- WEBhttps://lists.debian.org/debian-lts-announce/2020/11/msg00037.html
- WEBhttps://lists.debian.org/debian-lts-announce/2020/11/msg00038.html
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OCR6LAKCVKL55KJQPPBBWVQGOP7RL2RW/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WIRVUHD7TJIT7JJ33FKHIVTHPYABYPHR/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-15586
- WEBhttps://security.netapp.com/advisory/ntap-20200731-0005/
- WEBhttps://www.cloudfoundry.org/blog/cve-2020-15586/
- WEBhttps://www.debian.org/security/2021/dsa-4848
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html