CVE-2026-39825: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Go standard library net/http/httputil
CVE-2026-39825 is a medium severity vulnerability in the Go standard library's net/http/httputil ReverseProxy component. It involves inconsistent parsing of HTTP query parameters, where some parameters may be hidden from certain functions like Rewrite or Director but still forwarded by ReverseProxy. This leads to inconsistent interpretation of HTTP requests, classified as HTTP Request/Response Smuggling (CWE-444). No official patch or remediation guidance has been published, and no known exploits exist in the wild.
AI Analysis
Technical Summary
This vulnerability in the Go standard library's net/http/httputil ReverseProxy arises from differing parsing limits of HTTP query parameters. The ReverseProxy forwards requests containing query parameters that may be hidden from the Rewrite or Director functions due to inconsistent parsing. This discrepancy allows hidden parameters to be forwarded without detection, resulting in inconsistent interpretation of HTTP requests, a condition known as HTTP Request/Response Smuggling (CWE-444). The issue affects versions =0 and =1.26.0-0. No official remediation or patch has been released as of the publication date.
Potential Impact
The vulnerability allows hidden HTTP query parameters to be forwarded by the ReverseProxy component without detection by functions intended to inspect or modify requests. This inconsistent interpretation can lead to HTTP Request/Response Smuggling attacks, potentially causing security controls to be bypassed or requests to be misrouted. However, no known exploits have been reported in the wild, and the impact is limited to the confidentiality of query parameters (CVSS impact: Confidentiality Low, Integrity None, Availability None).
Mitigation Recommendations
No official patch or remediation guidance has been published by the Go project. Users should monitor the official Go project advisories for updates. Until a fix is available, careful review of ReverseProxy usage and additional validation of query parameters in application logic may help mitigate risks. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-39825: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Go standard library net/http/httputil
Description
CVE-2026-39825 is a medium severity vulnerability in the Go standard library's net/http/httputil ReverseProxy component. It involves inconsistent parsing of HTTP query parameters, where some parameters may be hidden from certain functions like Rewrite or Director but still forwarded by ReverseProxy. This leads to inconsistent interpretation of HTTP requests, classified as HTTP Request/Response Smuggling (CWE-444). No official patch or remediation guidance has been published, and no known exploits exist in the wild.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the Go standard library's net/http/httputil ReverseProxy arises from differing parsing limits of HTTP query parameters. The ReverseProxy forwards requests containing query parameters that may be hidden from the Rewrite or Director functions due to inconsistent parsing. This discrepancy allows hidden parameters to be forwarded without detection, resulting in inconsistent interpretation of HTTP requests, a condition known as HTTP Request/Response Smuggling (CWE-444). The issue affects versions =0 and =1.26.0-0. No official remediation or patch has been released as of the publication date.
Potential Impact
The vulnerability allows hidden HTTP query parameters to be forwarded by the ReverseProxy component without detection by functions intended to inspect or modify requests. This inconsistent interpretation can lead to HTTP Request/Response Smuggling attacks, potentially causing security controls to be bypassed or requests to be misrouted. However, no known exploits have been reported in the wild, and the impact is limited to the confidentiality of query parameters (CVSS impact: Confidentiality Low, Integrity None, Availability None).
Mitigation Recommendations
No official patch or remediation guidance has been published by the Go project. Users should monitor the official Go project advisories for updates. Until a fix is available, careful review of ReverseProxy usage and additional validation of query parameters in application logic may help mitigate risks. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-04-07T18:13:03.527Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fcf0c1cbff5d86102bd5d1
Added to database: 05/07/2026, 20:06:25 UTC
Last enriched: 06/24/2026, 17:18:43 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 94
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.