CVE-2015-5739: XSS

Published Aug 5, 2015
·
Updated

Go is vulnerable to HTTP request smuggling, caused by a flaw in net/http library in net/textproto/reader.go. By sending a specially-crafted HTTP request with a space instead of a hyphen, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.

Other sources

The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."

MITRE

There have been found potentially exploitable flaws in Golang net/http library affecting versions 1.4.2 and 1.5.

Problems: Double Content-length headers in a request does not generate a 400 error, the second Content-length is ignored. Invalid headers are parsed as valid headers (like "Content Length:" with a space in the middle)

Exploitations: In a situation where the net/http agent HTTP communication with the final http clients is using some reverse proxy (reverse proxy cache, SSL terminators, etc), some requests can be made exploiting the net/http HTTP protocol violations.

Attacker could possibly: bypass security controls on theses previous elements perform some cache poisoning on these elements alter the request/response map on these previous elements (for DOS)

CVE request: http://seclists.org/oss-sec/2015/q3/237

Upstream patches: https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9 https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f https://github.com/golang/go/commit/143822585e32449860e624cace9d2e521deee62e

Red Hat

Affected Software

18 affected componentsFixes available
redhat/golang<1.4.3
1.4.3
redhat/golang<1.5
1.5
Golang Go<=1.4.2
Fedoraproject Fedora=21
Fedoraproject Fedora=22
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.2
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6

Event History

Oct 18, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Feb 4, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-5739?

CVE-2015-5739 is considered moderate in severity due to its potential to allow HTTP request smuggling.

2

How do I fix CVE-2015-5739?

To fix CVE-2015-5739, upgrade the Go programming language to version 1.5 or later.

3

Which versions of Go are affected by CVE-2015-5739?

CVE-2015-5739 affects Go versions up to and including 1.4.2.

4

What types of attacks are possible due to CVE-2015-5739?

CVE-2015-5739 allows attackers to perform HTTP request smuggling, cache poisoning, and bypass web application firewall protections.

5

Which operating systems are impacted by CVE-2015-5739?

CVE-2015-5739 affects various versions of Red Hat Enterprise Linux and Fedora.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203