← Back to CVE List

CVE-2022-32148

Published: 2022-08-10T20:15Z
Last Modified: 2024-11-21T07:05Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt