
Go net/http impacted by CVE-2024-45336 and CVE-2023-29406, enabling sensitive headers leak on cross-domain redirects and unsafe Host header handling. Update affected apps. https://threatcluster.io/cluster/multiple-cves-affecting-nethttp-identified-in-2023-and-2024-d4ec619c
Post summary
The post announces that Go's net/http package is impacted by CVE-2024-45336 and CVE-2023-29406, which cause sensitive header leaks and unsafe Host handling, and urges users to update their applications.
