CVE-2023-29406

Published: August 31, 2023Last modified: July 22, 2025

Description

The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita LinuxStreamgoNot affected (1.21.0-r2)
Hardened ContainersStreamgoNot affected (1.21.0-r2)

References

ON THIS PAGE