CVE-2024-24791
Go vulnerability analysis and mitigation

Overview

CVE-2024-24791 is a vulnerability in the Go programming language's net/http package that affects versions prior to 1.21.12 and versions from 1.22.0-0 before 1.22.5. The vulnerability was discovered in May 2024 and publicly disclosed on July 2, 2024. It affects the HTTP/1.1 client implementation in the net/http package, specifically related to the handling of 'Expect: 100-continue' headers (Go Dev Blog).

Technical details

The vulnerability stems from the net/http HTTP/1.1 client's mishandling of cases where a server responds to a request with an 'Expect: 100-continue' header with a non-informational (200 or higher) status. This mishandling can leave a client connection in an invalid state, causing subsequent requests on that connection to fail. The vulnerability has been assigned a CVSS v3.1 score of 5.3 (Medium) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L (Red Hat CVE).

Impact

When exploited, this vulnerability can result in a denial of service condition. Specifically, when an attacker sends requests to a net/http/httputil.ReverseProxy proxy with 'Expect: 100-continue' headers that trigger non-informational responses from the backend, each request can invalidate a connection and cause subsequent requests using that connection to fail (Go Vuln DB).

Exploitability

The vulnerability can be exploited by sending specially crafted requests to systems using the affected Go versions, particularly those implementing reverse proxies using net/http/httputil.ReverseProxy. The attack requires no special privileges or user interaction, making it relatively straightforward to exploit (NetApp Security).

Mitigation and workarounds

The primary mitigation is to upgrade to Go versions 1.21.12 or 1.22.5 or later, which contain fixes for this vulnerability. The fix was implemented through a patch that addresses the improper handling of 100-continue responses (Go Dev Blog).

Additional resources


SourceThis report was generated using AI

Related Go vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-54365HIGH8.7
  • Go logoGo
  • trigger-dev
NoYesJun 23, 2026
CVE-2026-39822HIGH7.8
  • Go logoGo
  • kube-bench-fips
NoYesJul 08, 2026
CVE-2026-42504HIGH7.5
  • Go logoGo
  • commercial-expanso-edge
NoYesJun 02, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • kapacitor-fips-1.7
NoYesJul 08, 2026
CVE-2026-42507MEDIUM5.3
  • Go logoGo
  • authentik-fips-2025.12
NoYesJun 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management