← Volver al buscador de CVEs

CVE-2026-39825

Go ReverseProxy

Descripción

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery-s limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query -a1=x&a2=x&...&a10000=x&hidden=y- can forward the parameter -hidden=y- while hiding it from the proxy-s Rewrite function.

CVSS 5.3EPSS 0.38999999999999996%Riesgo 0.55
Ver fuente
Publicación
2026-05-07 20:16:43
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N