Skip to content

net/http: unvalidated trailer headers in Request #78775

@nicholashusin

Description

@nicholashusin

This originally came in as a security report (http://b/502454734 internally). However, exploiting this is implausible.
Therefore, this issue has been classified as security hardening effort.


When writing net/http.Request, its trailer headers are not validated and might contain control characters.

Metadata

Metadata

Assignees

No one assigned

    Labels

    NeedsFixThe path to resolution is known, but the work has not been done.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions