A vulnerability in Go's net/http package, tracked as CVE-2025-22871, can let malformed HTTP messages ending with a lone line feed be accepted instead of the required line ending, creating conditions for HTTP request smuggling when traffic is passed to another server that interprets the request differently. The issue affects server-side handling and has drawn differing severity assessments, with cve.org listing a CVSS 9.1 score while Red Hat rates impact on its products as Moderate with a CVSS v3 5.4 score.
Red Hat said exposure varies by product and noted that Red Hat Satellite is considered Low severity because it uses the affected Go component only as an HTTP client rather than as a server. The company reported that no acceptable mitigation is currently available under its product security criteria and published fixes for multiple affected packages, including Cryostat 4 on RHEL 9 components through advisory RHSA-2025:10323.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:11749 with updated Red Hat Ceph Storage 8.1 container images that fix CVE-2025-22871, the Go net/http request-smuggling flaw. The Important advisory also addressed six other vulnerabilities in bundled components.
Red Hat issued RHSA-2025:10781, an Important advisory providing OpenShift Container Platform 4.16.44 container-image updates for RHEL 9. The release fixes CVE-2025-22868 and the Go net/http request-smuggling flaw CVE-2025-22871, as well as CVE-2025-32462 in sudo.
Red Hat said fixes for CVE-2025-22871 were issued for Cryostat 4 on RHEL 9 components in RHSA-2025:10323, including multiple Cryostat-related packages.
Red Hat published its CVE entry for CVE-2025-22871, describing a Go net/http flaw that can enable HTTP request smuggling due to incorrect acceptance of LF-terminated messages.
Red Hat tracked CVE-2025-22871 as Bugzilla bug 2358493, reported on 2025-04-08, describing a Go net/http request smuggling flaw caused by acceptance of bare-LF-terminated chunk-size lines. The bug record also noted the upstream fixed versions as Go 1.24.2 and Go 1.23.8 and referenced the corresponding Go commits.
Red Hat tracked CVE-2025-22868 as Bugzilla bug 2348366, reported as a high-severity issue in golang.org/x/oauth2/jws. The flaw allows malformed tokens to trigger unexpected memory consumption during parsing, creating a denial-of-service risk.
Red Hat updated its CVE-2025-22871 entry, reflecting later changes to the advisory record.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.