Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-41721

25
FAUCET Score

CVE-2022-41721 describes a request smuggling vulnerability affecting Go's h2c server when using MaxBytesHandler. An attacker can manipulate unconsumed HTTP request body data to craft arbitrary HTTP/2 requests, potentially leading to denial-of-service. Rated 7.5 HIGH, this vulnerability has a low attack complexity and requires no user interaction or privileges, but its impact is limited to availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2022-11-04CPE matchmatch criteria
cpe:2.3:a:golang:h2c:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.81%
Probability of exploitation in next 30 days
EPSS Percentile
76.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0181 is in the 59th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

gopatch availablevia ghsa
Product: golang.org/x/netFixed in: 0.1.1-0.20221104162952-702349b0e862
microsoftpatch availablevia msrc
Product: cbl2 opa 0.50.2-5 on CBL Mariner 2.0Fixed in: 0.50.2-5
microsoftpatch availablevia msrc
Product: 19508-16823Fixed in: 0.50.2-5
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: openshift4/ose-thanos-rhel8:v4.13.0-202304190216.p0.gb6f11a5.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-hub-rhel9:6.2.0-16
View patch
redhatno patchvia redhat_api
Product: OpenShift ServerlessFixed in: knative-eventing
redhatno patchvia redhat_api
Product: OpenShift ServerlessFixed in: knative-serving
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/istio-cni-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/kube-rbac-proxy-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/thanos-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel8
redhatno patchvia redhat_api
Product: OpenShift ServerlessFixed in: CLI
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: osbuild-composer
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: osbuild-composer
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-kube-rbac-proxy
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8

Vendor Advisories (3)

goGHSA-fxg5-wq6x-vr4whigh

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

Jan 14, 2023
redhatCVE-2022-41721Moderate

x/net/http2/h2c: request smuggling

Jan 13, 2023
microsoft2023-Jan/CVE-2022-41721Important

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

Jan 10, 2023

References

go.dev / cl/447396
PatchVendor Advisory
go.dev / issue/56352
ExploitIssue TrackingPatchVendor Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/X3H3EWQXM2XL5AGBX6UL443JEJ3GQXJN
lists.fedoraproject.org / archives/list/[email protected]/message/X5DXTLLWN6HKI5I35EUZRBISTNZJ75GP
pkg.go.dev / vuln/GO-2023-1495
Vendor Advisory