2025-04-04
ALT-BU-2025-5149-2
Branch p10 update bulletin.
Closed vulnerabilities
Published: 2025-04-09
Modified: 2025-11-19
Modified: 2025-11-19
BDU:2025-04014
Уязвимость пакета net/http языка программирования Go, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнить произвольный код
Severity: CRITICAL (9.1)Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: CRITICAL (9.4)Vector: AV:N/AC:L/Au:N/C:C/I:C/A:N
References:
Published: 2025-04-08
Modified: 2026-04-15
Modified: 2026-04-15
CVE-2025-22871
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
Published: 2025-04-18
GHSA-5423-jcjm-2gpv
Traefik affected by Go HTTP Request Smuggling Vulnerability
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
- https://github.com/traefik/traefik/security/advisories/GHSA-5423-jcjm-2gpv
- https://nvd.nist.gov/vuln/detail/CVE-2025-22871
- https://github.com/traefik/traefik
- https://github.com/traefik/traefik/releases/tag/v2.11.24
- https://github.com/traefik/traefik/releases/tag/v3.3.6
- https://github.com/traefik/traefik/releases/tag/v3.4.0-rc2
Published: 2025-11-14
Modified: 2025-11-18
Modified: 2025-11-18
GHSA-6jqf-mv7m-3q7p
File Browser has risk of HTTP Request/Response smuggling through vulnerable dependency
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
Published: 2025-04-09
Modified: 2025-10-24
Modified: 2025-10-24
GHSA-g9pc-8g42-g6vq
RoadRunner is at risk of HTTP Request/Response Smuggling through vulnerable dependency
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References:
- https://nvd.nist.gov/vuln/detail/CVE-2025-22871
- https://github.com/roadrunner-server/roadrunner/issues/2166
- https://github.com/roadrunner-server/roadrunner/commit/f269279ee87d0b88127741cad1042389af7605fa
- https://github.com/roadrunner-server/roadrunner
- https://github.com/roadrunner-server/roadrunner/releases/tag/v2025.1.0
- https://go.dev/cl/652998
- https://go.dev/issue/71988
- https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk
- https://pkg.go.dev/vuln/GO-2025-3563
- http://www.openwall.com/lists/oss-security/2025/04/04/4
