CVE Explorer
CVE-2026-39825
ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a que
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://pkg.go.dev","defaultStatus":"unaffected","packageName":"net/http/httputil","product":"net/http/httputil","programRoutines":[{"name":"cleanQueryParams"},{"name":"ReverseProxy.ServeHTTP"}],"vendor":"Go standard library","versions":[{"lessThan":"1.25.10","status":"affected","version":"0","versionType":"semver"},{"lessThan":"1.26.3","status":"affected","version":"1.26.0-0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://go.dev/cl/770541"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/references/0
{"url":"https://go.dev/issue/78948"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/references/1
{"url":"https://groups.google.com/g/golang-announce/c/qcCIEXso47M"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/references/2
{"url":"https://pkg.go.dev/vuln/GO-2026-4976"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc2bb0ee7399774778d00294bc2a29205ecc99d9bb8e5d428881696e64427efa · sha256:a5b839a055fc69f6… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.