
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2025-22871 is a security vulnerability discovered in Go's net/http package. The vulnerability was disclosed on April 1, 2025, affecting Go versions before 1.23.8 and before 1.24.2. The issue involves the net/http package improperly accepting a bare LF (Line Feed) as a line terminator in chunked data chunk-size lines (Go Announce, NVD).
The vulnerability exists in the net/http package's handling of chunked transfer encoding. Specifically, the package incorrectly accepts data containing an invalid chunk-size line terminated by a bare LF. This implementation flaw could lead to request smuggling when the net/http server is used in conjunction with a server that incorrectly interprets a bare LF in a chunk extension as part of the extension (OSS Security, Go Issue).
The vulnerability can enable request smuggling attacks when the affected Go net/http server is used in combination with other servers that incorrectly handle bare LF characters in chunk extensions. This could potentially lead to unauthorized access or manipulation of HTTP requests (Go Vuln).
The issue has been fixed in Go versions 1.23.8 and 1.24.2. The fix involves modifying the net/http package to reject chunk-size lines containing a bare LF. Users are advised to upgrade to these patched versions to mitigate the vulnerability (Go Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”