
Go net/http impacted by CVE-2024-45336 and CVE-2023-29406, enabling sensitive headers leak on cross-domain redirects and unsafe Host header handling. Update affected apps. https://threatcluster.io/cluster/multiple-cves-affecting-nethttp-identified-in-2023-and-2024-d4ec619c
Post summary
The post reports that Go's net/http package suffers from CVE‑2024‑45336 and CVE‑2023‑29406, causing sensitive header leaks via cross‑domain redirects and unsafe Host handling, and urges users to update their applications.
