CVE-2026-94439
Public on 2026-10-08
Modified on 2026-10-10
Description
When an HTTP server handler sent a 2xx response to an HTTP/1 CONNECT request and returned without hijacking the connection, the server improperly continued to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.
The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.
The HTTP/1 server now always closes a connection after responding to a CONNECT request, regardless of the response status.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81744
NOTE: Fixed by: https://github.com/golang/go/commit/e92229e24a387cc006a750af176b07a459ba71a1 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/087de1ff08ea620ac2f6ae26c939454cb793883a (go1.26.9)
The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.
The HTTP/1 server now always closes a connection after responding to a CONNECT request, regardless of the response status.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81744
NOTE: Fixed by: https://github.com/golang/go/commit/e92229e24a387cc006a750af176b07a459ba71a1 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/087de1ff08ea620ac2f6ae26c939454cb793883a (go1.26.9)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2027 Preview | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | buildah | Pending Fix | ||
| Amazon Linux 2027 Preview | buildah | Pending Fix | ||
| Amazon Linux 2 - Core | cni-plugins | Pending Fix | ||
| Amazon Linux 2023 | cni-plugins | Pending Fix | ||
| Amazon Linux 2027 Preview | cni-plugins | Pending Fix | ||
| Amazon Linux 2 - Core | cri-tools | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | docker | Pending Fix | ||
| Amazon Linux 2023 | docker | Pending Fix | ||
| Amazon Linux 2027 Preview | docker | Pending Fix | ||
| Amazon Linux 2023 | git-lfs | Pending Fix | ||
| Amazon Linux 2027 Preview | git-lfs | Pending Fix | ||
| Amazon Linux 2 - Core | golang | Pending Fix | ||
| Amazon Linux 2023 | golang | Pending Fix | ||
| Amazon Linux 2027 Preview | golang | Pending Fix | ||
| Amazon Linux 2023 | libcap | Pending Fix | ||
| Amazon Linux 2027 Preview | libcap | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2027 Preview | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | skopeo | Pending Fix | ||
| Amazon Linux 2027 Preview | skopeo | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2027 Preview | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | yq | Pending Fix | ||
| Amazon Linux 2027 Preview | yq | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.8 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |