Go net/http Proxy Header Leakage Vulnerability on Cross-Origin Redirects

Vulnerability

A vulnerability exists in the Go programming language's net/http standard library, specifically in versions prior to 1.23.10 and between 1.24.0-0 and 1.24.4. This vulnerability involves the improper handling of Proxy-Authorization and Proxy-Authenticate headers during cross-origin redirects, which could lead to the unintentional leakage of sensitive information.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information through leaked proxy headers.

Remediation

Users can upgrade to Go versions 1.24.4 or 1.23.10 to address this vulnerability.

Added: Jun 11, 2025, 5:19 PM
Updated: Jun 11, 2025, 6:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
5.1
remediation
7.7
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.