CVE-2026-94439
Received Received - Intake

HTTP Server HTTP/1 CONNECT Request Handling Vulnerability

Vulnerability report for CVE-2026-94439, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Go standard library net/http 0
Go standard library net/http 1.27.0-0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an HTTP server misbehaving when handling HTTP/1 CONNECT requests. If the server sends a 2xx response to such a request but does not hijack the connection, it incorrectly continues to read and serve subsequent requests as if they were normal HTTP traffic. This is problematic because a 2xx response to a CONNECT request should convert the connection into a tunnel, meaning no further HTTP requests should be processed on that connection.

Impact Analysis

The primary impact is potential request smuggling. An attacker could exploit this to send malicious requests through the connection, which an intermediate proxy might treat as tunneled data while the server processes it as HTTP. This could lead to unauthorized access, data breaches, or other security issues depending on the server's configuration and the attacker's goals.

Compliance Impact

This vulnerability primarily enables request smuggling, which could allow unauthorized data access or manipulation. For GDPR, this may risk unauthorized data processing or breaches. For HIPAA, it could expose protected health information if request smuggling leads to data interception or tampering.

Mitigation Strategies

Update to the latest version of Go where this issue is fixed. Avoid using HTTP/1 CONNECT requests in your server handlers unless explicitly required for tunneling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94439. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart