CVE-2025-22871

CVE Details

Release Date:2025-04-08
Impact:Moderate What is this?

Description


The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

See more information about CVE-2025-22871 from MITRE CVE dictionary and NIST NVD


NOTE: The following CVSS metrics and score provided are preliminary and subject to review.


CVSS v3 metrics

Base Score: 5.4
Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Version: 3.1
Attack Vector: Network
Attack Complexity: High
Privileges Required: None
User Interaction: None
Scope: Changed
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None

Errata information


PlatformErrataRelease Date
Oracle Linux version 10 (buildah) ELSA-2025-91482025-06-27
Oracle Linux version 10 (delve) ELSA-2025-93172025-06-27
Oracle Linux version 10 (git-lfs) ELSA-2025-90632025-06-26
Oracle Linux version 10 (golang) ELSA-2025-84772025-06-27
Oracle Linux version 10 (golang-github-openprinting-ipp-usb) ELSA-2025-91562025-06-27
Oracle Linux version 10 (grafana) ELSA-2025-86662025-06-30
Oracle Linux version 10 (grafana-pcp) ELSA-2025-89152025-06-27
Oracle Linux version 10 (gvisor-tap-vsock) ELSA-2025-91512025-06-27
Oracle Linux version 10 (osbuild-composer) ELSA-2025-96232025-07-01
Oracle Linux version 10 (podman) ELSA-2025-91462025-06-27
Oracle Linux version 10 (skopeo) ELSA-2025-91492025-06-30
Oracle Linux version 8 (aardvark-dns) ELSA-2025-91422025-06-17
Oracle Linux version 8 (buildah) ELSA-2025-91422025-06-17
Oracle Linux version 8 (cockpit-podman) ELSA-2025-91422025-06-17
Oracle Linux version 8 (conmon) ELSA-2025-91422025-06-17
Oracle Linux version 8 (container-selinux) ELSA-2025-91422025-06-17
Oracle Linux version 8 (containernetworking-plugins) ELSA-2025-91422025-06-17
Oracle Linux version 8 (containers-common) ELSA-2025-91422025-06-17
Oracle Linux version 8 (criu) ELSA-2025-91422025-06-17
Oracle Linux version 8 (crun) ELSA-2025-91422025-06-17
Oracle Linux version 8 (delve) ELSA-2025-84782025-06-04
Oracle Linux version 8 (fuse-overlayfs) ELSA-2025-91422025-06-17
Oracle Linux version 8 (git-lfs) ELSA-2025-90602025-06-16
Oracle Linux version 8 (go-toolset) ELSA-2025-84782025-06-04
Oracle Linux version 8 (golang) ELSA-2025-84782025-06-04
Oracle Linux version 8 (grafana) ELSA-2025-86672025-06-09
Oracle Linux version 8 (grafana-pcp) ELSA-2025-89182025-06-11
Oracle Linux version 8 (libslirp) ELSA-2025-91422025-06-17
Oracle Linux version 8 (netavark) ELSA-2025-91422025-06-17
Oracle Linux version 8 (oci-seccomp-bpf-hook) ELSA-2025-91422025-06-17
Oracle Linux version 8 (osbuild-composer) ELSA-2025-98442025-06-27
Oracle Linux version 8 (podman) ELSA-2025-91422025-06-17
Oracle Linux version 8 (python-podman) ELSA-2025-91422025-06-17
Oracle Linux version 8 (runc) ELSA-2025-91422025-06-17
Oracle Linux version 8 (skopeo) ELSA-2025-91422025-06-17
Oracle Linux version 8 (slirp4netns) ELSA-2025-91422025-06-17
Oracle Linux version 8 (udica) ELSA-2025-91422025-06-17
Oracle Linux version 8 (weldr-client) ELSA-2025-98452025-06-26
Oracle Linux version 9 (buildah) ELSA-2025-91472025-06-17
Oracle Linux version 9 (containernetworking-plugins) ELSA-2025-91432025-06-16
Oracle Linux version 9 (git-lfs) ELSA-2025-91062025-06-16
Oracle Linux version 9 (golang) ELSA-2025-84762025-06-04
Oracle Linux version 9 (grafana) ELSA-2025-86822025-06-09
Oracle Linux version 9 (grafana-pcp) ELSA-2025-89162025-06-11
Oracle Linux version 9 (gvisor-tap-vsock) ELSA-2025-91502025-06-16
Oracle Linux version 9 (osbuild-composer) ELSA-2025-96342025-06-25
Oracle Linux version 9 (podman) ELSA-2025-91442025-06-17
Oracle Linux version 9 (skopeo) ELSA-2025-91452025-06-16
Oracle Linux version 9 (weldr-client) ELSA-2025-96352025-06-25


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete