4.3
CVSSv2

CVE-2019-9741

Published: 13/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go 1.11.5

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 29

redhat enterprise linux 8.0

redhat developer tools 1.0

Vendor Advisories

Debian Bug report logs - #924630 golang-111: CVE-2019-9741: CRLF injection in net/http Package: src:golang-111; Maintainer for src:golang-111 is Go Compiler Team <team+go-compiler@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 15 Mar 2019 07:57:01 UTC Severity: grave Tags: se ...
Synopsis Moderate: go-toolset:rhel8 security update Type/Severity Security Advisory: Moderate Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Moderate: go-toolset-111-golang security update Type/Severity Security Advisory: Moderate Topic An update for go-toolset-111 and go-toolset-111-golang is now available for Red Hat Developer ToolsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vul ...
An issue was discovered in net/http in Go CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to httpNewRequest with \r\n followed by an HTTP header or a Redis command (CVE-2019-9741) ...
Impact: Moderate Public Date: 2019-03-13 CWE: CWE-113 Bugzilla: 1688230: CVE-2019-9741 golang: CRLF inj ...