← Back

CVE-2016-5386

nvd nist
Published: Jul 19, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

Affected (8)

Show all products
1 product
Fedora
1 product
Linux
3 products
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
1 product
Go
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 23
Version 24
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Version 7.2
Version 7.2
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Golang
From 1.0 to 1.6.3
Version 1.7 rc1

References (18)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryUS Government Resource
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.