CVE-2021-36221

Related Vulnerabilities: CVE-2021-36221  

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

Description

The MITRE CVE dictionary describes this issue as:

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

Additional Information

  • Bugzilla 1995656: CVE-2021-36221 golang: panic due to racy read of persistConn after handler panic
  • FAQ: Frequently asked questions about CVE-2021-36221