CVE-2025-22871

EUVD-2025-11855
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensSENTRON 7KT PAC1261 Data Manager
𝑥
< V2.1.0
ADP
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
postponed
golang-1.19
bookworm
no-dsa
golang-1.24
trixie
1.24.4-1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
buildah
RHEL 9
2:1.39.4-2.el9_6
fixed
buildah-tests
RHEL 9
2:1.39.4-2.el9_6
fixed
containernetworking-plugins
RHEL 9
1:1.6.2-2.el9_6
fixed
git-lfs
RHEL 9
0:3.6.1-2.el9_6
fixed
go-toolset
RHEL 9
0:1.23.9-1.el9_6
fixed
golang
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-bin
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-docs
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-misc
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-race
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-src
RHEL 9
0:1.23.9-1.el9_6
fixed
golang-tests
RHEL 9
0:1.23.9-1.el9_6
fixed
grafana
RHEL 8
0:9.2.10-25.el8_10
fixed
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
RHEL 9
0:10.2.6-14.el9_6
fixed
grafana-azure-monitor
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-cloudwatch
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-elasticsearch
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-graphite
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-influxdb
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-loki
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-mssql
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-mysql
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-opentsdb
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-pcp
RHEL 9
0:5.1.1-11.el9_6
fixed
grafana-postgres
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-prometheus
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
grafana-selinux
RHEL 8
0:9.2.10-25.el8_10
fixed
RHEL 9
0:10.2.6-14.el9_6
fixed
grafana-stackdriver
RHEL 8.2 AUS
0:6.3.6-8.el8_2
fixed
gvisor-tap-vsock
RHEL 9
6:0.8.5-2.el9_6
fixed
gvisor-tap-vsock-gvforwarder
RHEL 9
6:0.8.5-2.el9_6
fixed
opentelemetry-collector
RHEL 9
0:0.127.0-1.el9_6
fixed
osbuild-composer
RHEL 8
0:101-4.el8_10
fixed
RHEL 8.4 AUS
0:28.7-3.el8_4
fixed
RHEL 8.6 AUS
0:46.3-3.el8_6
fixed
RHEL 8.6 E4S
0:46.3-3.el8_6
fixed
RHEL 8.6 TUS
0:46.3-3.el8_6
fixed
RHEL 8.8 E4S
0:75-4.el8_8
fixed
RHEL 8.8 TUS
0:75-4.el8_8
fixed
RHEL 9
0:132.2-2.el9_6
fixed
osbuild-composer-core
RHEL 8
0:101-4.el8_10
fixed
RHEL 8.4 AUS
0:28.7-3.el8_4
fixed
RHEL 8.6 AUS
0:46.3-3.el8_6
fixed
RHEL 8.6 E4S
0:46.3-3.el8_6
fixed
RHEL 8.6 TUS
0:46.3-3.el8_6
fixed
RHEL 8.8 E4S
0:75-4.el8_8
fixed
RHEL 8.8 TUS
0:75-4.el8_8
fixed
RHEL 9
0:132.2-2.el9_6
fixed
osbuild-composer-dnf-json
RHEL 8.6 AUS
0:46.3-3.el8_6
fixed
RHEL 8.6 E4S
0:46.3-3.el8_6
fixed
RHEL 8.6 TUS
0:46.3-3.el8_6
fixed
RHEL 8.8 E4S
0:75-4.el8_8
fixed
RHEL 8.8 TUS
0:75-4.el8_8
fixed
osbuild-composer-worker
RHEL 8
0:101-4.el8_10
fixed
RHEL 8.4 AUS
0:28.7-3.el8_4
fixed
RHEL 8.6 AUS
0:46.3-3.el8_6
fixed
RHEL 8.6 E4S
0:46.3-3.el8_6
fixed
RHEL 8.6 TUS
0:46.3-3.el8_6
fixed
RHEL 8.8 E4S
0:75-4.el8_8
fixed
RHEL 8.8 TUS
0:75-4.el8_8
fixed
RHEL 9
0:132.2-2.el9_6
fixed
podman
RHEL 9
5:5.4.0-10.el9_6
fixed
podman-docker
RHEL 9
5:5.4.0-10.el9_6
fixed
podman-plugins
RHEL 9
5:5.4.0-10.el9_6
fixed
podman-remote
RHEL 9
5:5.4.0-10.el9_6
fixed
podman-tests
RHEL 9
5:5.4.0-10.el9_6
fixed
skopeo
RHEL 9
2:1.18.1-2.el9_6
fixed
skopeo-tests
RHEL 9
2:1.18.1-2.el9_6
fixed
weldr-client
RHEL 9
0:35.12-4.el9_6
fixed