PatchSiren cyber security CVE debrief
CVE-2026-94439 Go standard library CVE debrief
A vulnerability in the Go standard library's net/http package allows for HTTP/1 server connection desynchronization after a 2xx CONNECT response. This issue can lead to potential request smuggling in certain scenarios. The vulnerability arises when an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, causing the server to improperly continue reading and serving requests from the connection. Defenders should assess exposure and prioritize patching or compensating controls.
- Vendor
- Go standard library
- Product
- stdlib
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Go applications using the net/http package should assess exposure and prioritize patching or compensating controls. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify affected versions, apply patches or compensating controls, and monitor for suspicious activity. Exposure requires verification from official sources due to limited information.
Why it matters
CVE-2026-94439 allows for HTTP/1 server connection desynchronization, potentially leading to request smuggling. Defenders should assess exposure, prioritize patching, and implement compensating controls.
- Request smuggling may occur due to improper connection handling.
- Defenders should verify affected versions and apply patches or compensating controls.
- Exposure requires verification from official sources due to limited information.
Technical summary
The Go standard library's net/http package does not properly handle 2xx responses to HTTP/1 CONNECT requests, leading to potential request smuggling. This issue arises from the improper handling of connections after a 2xx response, allowing for potential request smuggling attacks. Defenders should assess exposure and prioritize patching or compensating controls to mitigate this vulnerability. The vulnerability has been addressed in versions 1.26.9 and 1.27.2 of the Go standard library. Official sources provide details on affected versions and patches.
Defensive priority
Defenders should prioritize assessing exposure and implementing compensating controls, as the impact is mostly limited to request smuggling.
Recommended defensive actions
- Assess exposure and prioritize patching for systems using the affected Go standard library versions.
- Implement compensating controls to detect and prevent request smuggling attacks.
- Monitor for suspicious activity and adjust detection rules as necessary.
- Review and update incident response plans to address potential request smuggling attacks.
- Verify affected versions and apply patches or compensating controls.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Conduct a thorough review of the environment to identify potential exposure.
Evidence notes
The vulnerability is described in the Go issue tracker and has been addressed in versions 1.26.9 and 1.27.2. The impact is mostly limited to potential request smuggling. Official sources confirm the vulnerability and provide details on affected versions and patches. Defenders should verify affected versions and apply patches or compensating controls.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94439 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94439
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94439 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94439
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GO-2026-6613.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://go.dev/cl/847311
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://go.dev/issue/81744
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/g/golang-announce/c/U2fTuyDJznI
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.