Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

net/http: security fixes for 1.4.3 #12741

broady opened this issue Sep 24, 2015 · 1 comment

net/http: security fixes for 1.4.3 #12741

broady opened this issue Sep 24, 2015 · 1 comment


Copy link

@broady broady commented Sep 24, 2015

"Content Length" treated as valid header:

Double content-length headers does not return 400 error:

Additional hardening, not sending Content-Length w/Transfer-Encoding,
Closing connections:

The Go team would like to thank Jed Denlea and Régis Leroy for their contributions to this release. They have been awarded 1337 USD under the Google Security Bounty program.

@broady broady closed this Sep 24, 2015
@ianlancetaylor ianlancetaylor added this to the Go1.4.3 milestone Sep 24, 2015
@golang golang locked and limited conversation to collaborators Sep 24, 2016
@dvyukov dvyukov added the Security label May 15, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants
You can’t perform that action at this time.