golang
cpe:2.3:a:golang:go:*:*:*:*:*:*:*
- < go1.23.10
- >= go1.24.0-0, < go1.24.4
A vulnerability exists in the Go programming language's net/http standard library, specifically in versions prior to 1.23.10 and between 1.24.0-0 and 1.24.4. This vulnerability involves the improper handling of Proxy-Authorization and Proxy-Authenticate headers during cross-origin redirects, which could lead to the unintentional leakage of sensitive information.
Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information through leaked proxy headers.
Users can upgrade to Go versions 1.24.4 or 1.23.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.