/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-24qm-38v9-w9fq

Published

Last updated

https://images.chainguard.dev/security/CGA-24qm-38v9-w9fq
Package

traefik-fips-3.2

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • GHSA-5423-jcjm-2gpv

Severity

Unknown

Summary

Traefik affected by Go HTTP Request Smuggling Vulnerability

Description

Summary

net/http: request smuggling through invalid chunked data: The net/http package accepts data in the chunked transfer encoding containing an invalid chunk-size line terminated by a bare LF. When used in conjunction with a server or proxy which incorrectly interprets a bare LF in a chunk extension as part of the extension, this could permit request smuggling. [CVE-2025-22871] Vendor Affected Components: Go: 1.23.x < 1.23.8

More Details: CVE-2025-22871

Patches

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs