Gohttp Project maintains a narrowly focused HTTP client library that serves as a component in downstream applications, with its vulnerability profile centered on memory-safety issues including out-of-bounds reads, out-of-bounds writes, and use-after-free conditions characteristic of native code implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gohttp Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12160CRITICAL GoHTTP through 2017-07-25 has a sendHeader use-after-free. | May 17, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-12158CRITICAL GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension. | May 17, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-12198HIGH In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header. | May 20, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-12159HIGH GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via a long URL. | May 17, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gohttp Project.
Media articles that mention a CVE ID that affects a product developed by Gohttp Project — matched by CVE ID, not by vendor name.