CVE-2026-56866

Public on 2026-10-08
Modified on 2026-10-10
Description
When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.

The HTTP/1 transport now closes a connection after sending a CONNECT request, regardless of the response status.

In addition, ReverseProxy now rejects incoming CONNECT requests with a 405 Method Not Allowed response. ReverseProxy has never handled CONNECT requests in a useful fashion (it does not convert the connection into a bidirectional tunnel), so we do not expect this change to negatively affect any current users.

NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81740
NOTE: Fixed by: https://github.com/golang/go/commit/76875df0f3425f69e4dc2c439040a248b6107854 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/3fe1aac0ce941cb16b0ec5d489827cf1c58197c4 (go1.26.9)
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core golang Pending Fix
Amazon Linux 2 - Golang1.11 Extra golang No Fix Planned
Amazon Linux 2 - Golang1.19 Extra golang No Fix Planned
Amazon Linux 2 - Golang1.9 Extra golang No Fix Planned
Amazon Linux 2023 golang Pending Fix
Amazon Linux 2027 Preview golang Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N