PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94439 Go standard library CVE debrief

A vulnerability in the Go standard library's net/http package allows for HTTP/1 server connection desynchronization after a 2xx CONNECT response. This issue can lead to potential request smuggling in certain scenarios. The vulnerability arises when an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, causing the server to improperly continue reading and serving requests from the connection. Defenders should assess exposure and prioritize patching or compensating controls.

Vendor
Go standard library
Product
stdlib
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Go applications using the net/http package should assess exposure and prioritize patching or compensating controls. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify affected versions, apply patches or compensating controls, and monitor for suspicious activity. Exposure requires verification from official sources due to limited information.

Why it matters

CVE-2026-94439 allows for HTTP/1 server connection desynchronization, potentially leading to request smuggling. Defenders should assess exposure, prioritize patching, and implement compensating controls.

  • Request smuggling may occur due to improper connection handling.
  • Defenders should verify affected versions and apply patches or compensating controls.
  • Exposure requires verification from official sources due to limited information.

Technical summary

The Go standard library's net/http package does not properly handle 2xx responses to HTTP/1 CONNECT requests, leading to potential request smuggling. This issue arises from the improper handling of connections after a 2xx response, allowing for potential request smuggling attacks. Defenders should assess exposure and prioritize patching or compensating controls to mitigate this vulnerability. The vulnerability has been addressed in versions 1.26.9 and 1.27.2 of the Go standard library. Official sources provide details on affected versions and patches.

Defensive priority

Defenders should prioritize assessing exposure and implementing compensating controls, as the impact is mostly limited to request smuggling.

Recommended defensive actions

  • Assess exposure and prioritize patching for systems using the affected Go standard library versions.
  • Implement compensating controls to detect and prevent request smuggling attacks.
  • Monitor for suspicious activity and adjust detection rules as necessary.
  • Review and update incident response plans to address potential request smuggling attacks.
  • Verify affected versions and apply patches or compensating controls.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Conduct a thorough review of the environment to identify potential exposure.

Evidence notes

The vulnerability is described in the Go issue tracker and has been addressed in versions 1.26.9 and 1.27.2. The impact is mostly limited to potential request smuggling. Official sources confirm the vulnerability and provide details on affected versions and patches. Defenders should verify affected versions and apply patches or compensating controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94439 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94439

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94439 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94439

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.