← Back to Resources
Open Source NewsApril 1, 20252 min read

Go Security Fix for net/http Request Smuggling

By BIOS Founding Team

Go Security Fix for net/http Request Smuggling

These releases patched a vulnerability where net/http improperly accepted a bare LF as a chunked-encoding line terminator, enabling request smuggling when chained with non-compliant servers.

Both point releases also carried assorted compiler, runtime, and go-command bug fixes.

Full details: https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk