CVE-2024-45258

critical

Description

The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.

References

https://github.com/imroc/req/compare/v3.43.3...v3.43.4

https://github.com/imroc/req/commit/04e3ece5b380ecad9da3551c449f1b8a9aa76d3d

Details

Source: Mitre, NVD

Published: 2024-08-25

Updated: 2024-08-26

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical