
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in Go versions before 1.15.13 and 1.16.x before 1.16.5, affecting the ReverseProxy functionality in the net/http/httputil package. The vulnerability was assigned CVE-2021-33197 and was disclosed in June 2021 (Golang Announce).
The vulnerability exists in the ReverseProxy component where certain configurations could allow an attacker to forward specific hop-by-hop headers, including Connection headers, if the first one was empty. This becomes particularly dangerous when the target of the ReverseProxy is itself a reverse proxy, as it would enable an attacker to drop arbitrary headers, including those set by the ReverseProxy.Director (Golang Announce).
When exploited, this vulnerability allows attackers to manipulate HTTP headers by dropping arbitrary headers in certain proxy configurations. This could potentially lead to security bypass or header manipulation attacks, particularly in multi-proxy setups (Red Hat CVE).
The vulnerability has been fixed in Go versions 1.15.13 and 1.16.5. Users are advised to upgrade to these or later versions to address the security issue. The fix prevents the unintended forwarding of connection headers in reverse proxy configurations (Golang Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."