VYPR
Medium severity6.1OSV Advisory· Published Mar 13, 2019· Updated Jun 17, 2026

CVE-2019-9741

CVE-2019-9741

Description

An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Golang/GoOSV3 versions
    go1.10beta1, go1.10beta2, go1.10rc1, …+ 2 more
    • (no CPE)range: go1.10beta1, go1.10beta2, go1.10rc1, …
    • cpe:2.3:a:golang:go:1.11.5:*:*:*:*:*:*:*
    • (no CPE)range: <=1.11.5
  • cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:*
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.