Related Vulnerabilities: CVE-2021-33197  

A security issue has been found in Go before version 1.16.5. ReverseProxy in net/http/httputil could be made to forward certain hop-by-hop headers, including Connection. In case the target of the ReverseProxy was itself a reverse proxy, this would let an attacker drop arbitrary headers, including those set by the ReverseProxy.Director.

Severity Medium

Remote Yes

Type Url request injection

Description

A security issue has been found in Go before version 1.16.5. ReverseProxy in net/http/httputil could be made to forward certain hop-by-hop headers, including Connection. In case the target of the ReverseProxy was itself a reverse proxy, this would let an attacker drop arbitrary headers, including those set by the ReverseProxy.Director.

AVG-2006 go 2:1.16.4-1 Medium Vulnerable

https://groups.google.com/g/golang-announce/c/RgCMkAEQjSI/m/r_EP-NlKBgAJ
https://github.com/golang/go/issues/46313
https://github.com/golang/go/commit/0410005dc458f23fb15f64354f9a24ca8f2fe044