First published: Tue Jul 12 2022(Updated: )
A flaw was found in golang. The HTTP/1 client accepted invalid Transfer-Encoding headers indicating "chunked" encoding. This issue could allow request smuggling, but only if combined with an intermediate server that also improperly accepts the header as invalid.
Credit: security@golang.org security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/skupper-cli | <0:1.0.2-2.el8 | 0:1.0.2-2.el8 |
redhat/libsodium | <0:1.0.16-5.el8 | 0:1.0.16-5.el8 |
redhat/openstack-ironic | <1:20.2.1-0.20220628175043.b5ed57a.el8 | 1:20.2.1-0.20220628175043.b5ed57a.el8 |
redhat/openstack-ironic-inspector | <0:10.12.1-0.20220513095437.6dd37e5.el8 | 0:10.12.1-0.20220513095437.6dd37e5.el8 |
redhat/openstack-ironic-python-agent | <0:8.6.1-0.20220623075054.1d50c23.el8 | 0:8.6.1-0.20220623075054.1d50c23.el8 |
redhat/pyparsing | <0:2.3.1-2.el8 | 0:2.3.1-2.el8 |
redhat/pysnmp | <0:4.4.8-3.el8 | 0:4.4.8-3.el8 |
redhat/python-alembic | <0:1.4.2-6.el8 | 0:1.4.2-6.el8 |
redhat/python-amqp | <0:2.5.2-8.el8 | 0:2.5.2-8.el8 |
redhat/python-appdirs | <0:1.4.0-8.el8 | 0:1.4.0-8.el8 |
redhat/python-automaton | <0:2.5.0-0.20220509195848.aaca110.el8 | 0:2.5.0-0.20220509195848.aaca110.el8 |
redhat/python-bcrypt | <0:3.1.6-3.el8 | 0:3.1.6-3.el8 |
redhat/python-beautifulsoup4 | <0:4.9.3-2.el8 | 0:4.9.3-2.el8 |
redhat/python-cachetools | <0:3.1.0-3.el8 | 0:3.1.0-3.el8 |
redhat/python-cinderclient | <0:8.3.0-0.20220509212734.ee59b68.el8 | 0:8.3.0-0.20220509212734.ee59b68.el8 |
redhat/python-cliff | <0:3.10.1-0.20220509200732.a04a48f.el8 | 0:3.10.1-0.20220509200732.a04a48f.el8 |
redhat/python-colorama | <0:0.4.1-2.el8 | 0:0.4.1-2.el8 |
redhat/python-construct | <0:2.10.56-2.el8 | 0:2.10.56-2.el8 |
redhat/python-dataclasses | <0:0.8-3.el8 | 0:0.8-3.el8 |
redhat/python-debtcollector | <0:2.5.0-0.20220509211533.a6b46c5.el8 | 0:2.5.0-0.20220509211533.a6b46c5.el8 |
redhat/python-decorator | <0:4.4.0-6.el8 | 0:4.4.0-6.el8 |
redhat/python-dogpile-cache | <0:1.1.2-2.el8 | 0:1.1.2-2.el8 |
redhat/python-dracclient | <0:8.0.0-0.20220509201613.9c7499c.el8 | 0:8.0.0-0.20220509201613.9c7499c.el8 |
redhat/python-editor | <0:1.0.4-5.el8 | 0:1.0.4-5.el8 |
redhat/python-fasteners | <0:0.14.1-21.el8 | 0:0.14.1-21.el8 |
redhat/python-flask | <1:1.1.1-2.el8 | 1:1.1.1-2.el8 |
redhat/python-funcsigs | <0:1.0.2-17.el8 | 0:1.0.2-17.el8 |
redhat/python-futurist | <0:2.4.1-0.20220509215250.159d752.el8 | 0:2.4.1-0.20220509215250.159d752.el8 |
redhat/python-glanceclient | <1:3.6.0-0.20220509212414.626c500.el8 | 1:3.6.0-0.20220509212414.626c500.el8 |
redhat/python-greenlet | <0:0.4.14-6.el8 | 0:0.4.14-6.el8 |
redhat/python-hardware | <0:0.29.0-0.20220216015636.7662a1d.el8 | 0:0.29.0-0.20220216015636.7662a1d.el8 |
redhat/python-ifaddr | <0:0.1.6-6.el8 | 0:0.1.6-6.el8 |
redhat/python-importlib-metadata | <0:1.7.0-2.el8 | 0:1.7.0-2.el8 |
redhat/python-ironic-lib | <0:5.1.1-0.20220225151335.e205816.el8 | 0:5.1.1-0.20220225151335.e205816.el8 |
redhat/python-ironic-prometheus-exporter | <0:3.1.1-0.20220324125409.db1a824.el8 | 0:3.1.1-0.20220324125409.db1a824.el8 |
redhat/python-iso8601 | <0:0.1.12-9.el8 | 0:0.1.12-9.el8 |
redhat/python-jsonpath-rw | <0:1.2.3-23.el8 | 0:1.2.3-23.el8 |
redhat/python-jsonschema | <0:3.2.0-6.el8 | 0:3.2.0-6.el8 |
redhat/python-kazoo | <0:2.7.0-2.el8 | 0:2.7.0-2.el8 |
redhat/python-keyring | <0:21.0.0-2.el8 | 0:21.0.0-2.el8 |
redhat/python-keystoneauth1 | <0:4.5.0-0.20220509213157.8da0a63.el8 | 0:4.5.0-0.20220509213157.8da0a63.el8 |
redhat/python-keystoneclient | <1:4.4.0-0.20220509200759.100253d.el8 | 1:4.4.0-0.20220509200759.100253d.el8 |
redhat/python-keystonemiddleware | <0:9.4.0-0.20220509211054.8a05709.el8 | 0:9.4.0-0.20220509211054.8a05709.el8 |
redhat/python-kombu | <1:4.6.6-8.el8 | 1:4.6.6-8.el8 |
redhat/python-logutils | <0:0.3.5-7.1.el8 | 0:0.3.5-7.1.el8 |
redhat/python-memcached | <0:1.58-12.el8 | 0:1.58-12.el8 |
redhat/python-migrate | <0:0.13.0-2.el8 | 0:0.13.0-2.el8 |
redhat/python-msgpack | <0:0.6.2-2.el8 | 0:0.6.2-2.el8 |
redhat/python-munch | <0:2.3.2-7.el8 | 0:2.3.2-7.el8 |
redhat/python-openstacksdk | <0:0.61.0-0.20220509201549.26c9bc2.el8 | 0:0.61.0-0.20220509201549.26c9bc2.el8 |
redhat/python-osc-lib | <0:2.5.0-0.20220509211843.78d276e.el8 | 0:2.5.0-0.20220509211843.78d276e.el8 |
redhat/python-oslo-cache | <0:2.8.1-0.20220216000746.40946a9.el8 | 0:2.8.1-0.20220216000746.40946a9.el8 |
redhat/python-oslo-concurrency | <0:4.5.1-0.20220509221157.145f060.el8 | 0:4.5.1-0.20220509221157.145f060.el8 |
redhat/python-oslo-config | <2:8.8.0-0.20220509202553.64c82a0.el8 | 2:8.8.0-0.20220509202553.64c82a0.el8 |
redhat/python-oslo-context | <0:4.1.0-0.20220509205437.3400cc2.el8 | 0:4.1.0-0.20220509205437.3400cc2.el8 |
redhat/python-oslo-db | <0:9.1.0-0.20220216003829.be2cc6a.el8 | 0:9.1.0-0.20220216003829.be2cc6a.el8 |
redhat/python-oslo-i18n | <0:5.1.0-0.20220216011159.b031d17.el8 | 0:5.1.0-0.20220216011159.b031d17.el8 |
redhat/python-oslo-log | <0:4.6.0-0.20220216002407.41c8807.el8 | 0:4.6.0-0.20220216002407.41c8807.el8 |
redhat/python-oslo-messaging | <0:12.13.0-0.20220509210748.2d090b5.el8 | 0:12.13.0-0.20220509210748.2d090b5.el8 |
redhat/python-oslo-metrics | <0:0.3.0-0.20220216012738.43eee50.el8 | 0:0.3.0-0.20220216012738.43eee50.el8 |
redhat/python-oslo-middleware | <0:4.5.1-0.20220509203328.2f72b30.el8 | 0:4.5.1-0.20220509203328.2f72b30.el8 |
redhat/python-oslo-policy | <0:3.12.1-0.20220509221328.9673a74.el8 | 0:3.12.1-0.20220509221328.9673a74.el8 |
redhat/python-oslo-rootwrap | <0:6.3.1-0.20220509204453.1b1b960.el8 | 0:6.3.1-0.20220509204453.1b1b960.el8 |
redhat/python-oslo-serialization | <0:4.3.0-0.20220509195921.6910f75.el8 | 0:4.3.0-0.20220509195921.6910f75.el8 |
redhat/python-oslo-service | <0:2.8.0-0.20220509203713.6552b9a.el8 | 0:2.8.0-0.20220509203713.6552b9a.el8 |
redhat/python-oslo-upgradecheck | <0:1.5.0-0.20220509195112.1559e03.el8 | 0:1.5.0-0.20220509195112.1559e03.el8 |
redhat/python-oslo-utils | <0:4.13.0-0.20220509213520.de4429f.el8 | 0:4.13.0-0.20220509213520.de4429f.el8 |
redhat/python-oslo-versionedobjects | <0:2.6.0-0.20220509202736.25d34d6.el8 | 0:2.6.0-0.20220509202736.25d34d6.el8 |
redhat/python-osprofiler | <0:3.4.3-0.20220509214403.3286301.el8 | 0:3.4.3-0.20220509214403.3286301.el8 |
redhat/python-os-service-types | <0:1.7.0-0.20220215231659.0b2f473.el8 | 0:1.7.0-0.20220215231659.0b2f473.el8 |
redhat/python-os-traits | <0:2.7.0-0.20220509205801.3d1dbf0.el8 | 0:2.7.0-0.20220509205801.3d1dbf0.el8 |
redhat/python-packaging | <0:20.4-2.el8 | 0:20.4-2.el8 |
redhat/python-paste | <0:3.2.4-2.el8 | 0:3.2.4-2.el8 |
redhat/python-paste-deploy | <0:2.0.1-5.el8 | 0:2.0.1-5.el8 |
redhat/python-pbr | <0:5.5.1-2.el8 | 0:5.5.1-2.el8 |
redhat/python-pecan | <0:1.3.2-10.el8 | 0:1.3.2-10.el8 |
redhat/python-pexpect | <0:4.6-3.el8 | 0:4.6-3.el8 |
redhat/python-pint | <0:0.10.1-3.el8 | 0:0.10.1-3.el8 |
redhat/python-proliantutils | <0:2.13.2-0.20220509214147.8c7b6b1.el8 | 0:2.13.2-0.20220509214147.8c7b6b1.el8 |
redhat/python-pycadf | <0:3.1.1-0.20220215232623.4179996.el8 | 0:3.1.1-0.20220215232623.4179996.el8 |
redhat/python-pycdlib | <0:1.11.0-4.el8 | 0:1.11.0-4.el8 |
redhat/python-pynacl | <0:1.3.0-6.el8 | 0:1.3.0-6.el8 |
redhat/python-pyperclip | <0:1.6.4-7.el8 | 0:1.6.4-7.el8 |
redhat/python-pyrsistent | <0:0.16.0-4.el8 | 0:0.16.0-4.el8 |
redhat/python-redis | <0:3.3.8-2.el8 | 0:3.3.8-2.el8 |
redhat/python-repoze-lru | <0:0.7-7.el8 | 0:0.7-7.el8 |
redhat/python-requestsexceptions | <0:1.4.0-0.20220215231659.d7ac0ff.el8 | 0:1.4.0-0.20220215231659.d7ac0ff.el8 |
redhat/python-retrying | <0:1.2.3-22.el8 | 0:1.2.3-22.el8 |
redhat/python-rfc3986 | <0:1.2.0-6.el8 | 0:1.2.0-6.el8 |
redhat/python-routes | <0:2.4.1-12.el8 | 0:2.4.1-12.el8 |
redhat/python-scciclient | <0:0.11.1-0.20220216020832.a84332b.el8 | 0:0.11.1-0.20220216020832.a84332b.el8 |
redhat/python-simplegeneric | <0:0.8.1-18.el8 | 0:0.8.1-18.el8 |
redhat/python-simplejson | <0:3.17.0-2.el8 | 0:3.17.0-2.el8 |
redhat/python-singledispatch | <0:3.4.0.3-19.el8 | 0:3.4.0.3-19.el8 |
redhat/python-six | <0:1.15.0-3.el8 | 0:1.15.0-3.el8 |
redhat/python-soupsieve | <0:2.1.0-2.el8 | 0:2.1.0-2.el8 |
redhat/python-sqlparse | <0:0.2.4-10.el8 | 0:0.2.4-10.el8 |
redhat/python-statsd | <0:3.2.1-17.el8 | 0:3.2.1-17.el8 |
redhat/python-stevedore | <0:3.5.0-0.20220509195112.442f157.el8 | 0:3.5.0-0.20220509195112.442f157.el8 |
redhat/python-sushy | <0:4.1.1-0.20220302175405.c769149.el8 | 0:4.1.1-0.20220302175405.c769149.el8 |
redhat/python-sushy-oem-idrac | <0:4.0.0-0.20220324125409.7b75e6e.el8 | 0:4.0.0-0.20220324125409.7b75e6e.el8 |
redhat/python-swiftclient | <0:3.13.1-0.20220509204112.4989d94.el8 | 0:3.13.1-0.20220509204112.4989d94.el8 |
redhat/python-tempita | <0:0.5.1-25.el8 | 0:0.5.1-25.el8 |
redhat/python-tenacity | <0:6.2.0-2.el8 | 0:6.2.0-2.el8 |
redhat/python-tooz | <0:2.11.1-0.20220509215238.96f91b9.el8 | 0:2.11.1-0.20220509215238.96f91b9.el8 |
redhat/python-vine | <0:1.3.0-5.el8 | 0:1.3.0-5.el8 |
redhat/python-voluptuous | <0:0.11.7-3.el8 | 0:0.11.7-3.el8 |
redhat/python-waitress | <0:2.0.0-2.el8 | 0:2.0.0-2.el8 |
redhat/python-warlock | <0:1.3.3-2.el8 | 0:1.3.3-2.el8 |
redhat/python-wcwidth | <0:0.1.7-15.el8 | 0:0.1.7-15.el8 |
redhat/python-webob | <0:1.8.5-5.el8 | 0:1.8.5-5.el8 |
redhat/python-webtest | <0:2.0.33-5.el8 | 0:2.0.33-5.el8 |
redhat/python-werkzeug | <0:2.0.3-1.el8 | 0:2.0.3-1.el8 |
redhat/python-wrapt | <0:1.11.2-4.el8 | 0:1.11.2-4.el8 |
redhat/python-wsme | <0:0.11.0-0.20220216004816.80bda90.el8 | 0:0.11.0-0.20220216004816.80bda90.el8 |
redhat/python-yappi | <0:1.0-3.el8 | 0:1.0-3.el8 |
redhat/python-zake | <0:0.2.2-19.el8 | 0:0.2.2-19.el8 |
redhat/python-zeroconf | <0:0.24.4-2.el8 | 0:0.24.4-2.el8 |
redhat/python-zipp | <0:0.5.1-3.el8 | 0:0.5.1-3.el8 |
redhat/openshift-serverless-clients | <0:1.3.1-4.el8 | 0:1.3.1-4.el8 |
redhat/go-toolset | <1.17-golang-0:1.17.12-1.el7_9 | 1.17-golang-0:1.17.12-1.el7_9 |
redhat/git-lfs | <0:2.13.3-3.el8_6 | 0:2.13.3-3.el8_6 |
redhat/grafana | <0:7.5.15-3.el8 | 0:7.5.15-3.el8 |
redhat/grafana-pcp | <0:3.2.0-2.el8 | 0:3.2.0-2.el8 |
redhat/golang | <0:1.17.12-1.el9_0 | 0:1.17.12-1.el9_0 |
redhat/grafana | <0:7.5.15-3.el9 | 0:7.5.15-3.el9 |
redhat/toolbox | <0:0.0.99.3-5.el9 | 0:0.0.99.3-5.el9 |
redhat/grafana-pcp | <0:3.2.0-3.el9 | 0:3.2.0-3.el9 |
redhat/git-lfs | <0:3.2.0-1.el9 | 0:3.2.0-1.el9 |
redhat/atomic-openshift-service-idler | <0:4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8 | 0:4.11.0-202206222028.p0.g39cfc66.assembly.stream.el8 |
redhat/buildah | <1:1.23.4-2.el8 | 1:1.23.4-2.el8 |
redhat/butane | <0:0.15.0-1.rhaos4.11.el8 | 0:0.15.0-1.rhaos4.11.el8 |
redhat/conmon | <2:2.1.2-2.rhaos4.11.el8 | 2:2.1.2-2.rhaos4.11.el8 |
redhat/console-login-helper-messages | <0:0.20.3-2.rhaos4.11.el8 | 0:0.20.3-2.rhaos4.11.el8 |
redhat/containernetworking-plugins | <0:1.0.1-5.rhaos4.11.el8 | 0:1.0.1-5.rhaos4.11.el8 |
redhat/containers-common | <2:1-21.rhaos4.11.el8 | 2:1-21.rhaos4.11.el8 |
redhat/container-selinux | <2:2.188.0-1.rhaos4.11.el8 | 2:2.188.0-1.rhaos4.11.el8 |
redhat/coreos-installer | <0:0.15.0-2.rhaos4.11.el8 | 0:0.15.0-2.rhaos4.11.el8 |
redhat/cri-o | <0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8 | 0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8 |
redhat/cri-tools | <0:1.24.2-4.1.el8 | 0:1.24.2-4.1.el8 |
redhat/criu | <0:3.15-4.rhaos4.11.el8 | 0:3.15-4.rhaos4.11.el8 |
redhat/crun | <0:1.4.2-1.rhaos4.11.el8 | 0:1.4.2-1.rhaos4.11.el8 |
redhat/fuse-overlayfs | <0:1.9-1.rhaos4.11.el8 | 0:1.9-1.rhaos4.11.el8 |
redhat/haproxy | <0:2.2.24-1.el8 | 0:2.2.24-1.el8 |
redhat/ignition | <0:2.14.0-3.rhaos4.11.el8 | 0:2.14.0-3.rhaos4.11.el8 |
redhat/kata-containers | <0:2.4.2-1.el8 | 0:2.4.2-1.el8 |
redhat/libslirp | <0:4.4.0-2.rhaos4.11.el8 | 0:4.4.0-2.rhaos4.11.el8 |
redhat/openshift | <0:4.11.0-202207082037.p0.g9546431.assembly.stream.el8 | 0:4.11.0-202207082037.p0.g9546431.assembly.stream.el8 |
redhat/openshift-ansible | <0:4.11.0-202206240216.p0.g9de1722.assembly.stream.el8 | 0:4.11.0-202206240216.p0.g9de1722.assembly.stream.el8 |
redhat/openshift-clients | <0:4.11.0-202207291716.p0.g7075089.assembly.stream.el8 | 0:4.11.0-202207291716.p0.g7075089.assembly.stream.el8 |
redhat/openshift-kuryr | <0:4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8 | 0:4.11.0-202206232036.p0.g66c0cec.assembly.stream.el8 |
redhat/openvswitch2.17 | <0:2.17.0-22.el8fd | 0:2.17.0-22.el8fd |
redhat/ovn22.03 | <0:22.03.0-37.el8fd | 0:22.03.0-37.el8fd |
redhat/ovn22.06 | <0:22.06.0-27.el8fd | 0:22.06.0-27.el8fd |
redhat/podman | <2:4.0.2-6.rhaos4.11.el8 | 2:4.0.2-6.rhaos4.11.el8 |
redhat/runc | <3:1.1.2-1.rhaos4.11.el8 | 3:1.1.2-1.rhaos4.11.el8 |
redhat/rust-afterburn | <0:5.3.0-1.rhaos4.11.el8 | 0:5.3.0-1.rhaos4.11.el8 |
redhat/rust-bootupd | <0:0.2.5-3.rhaos4.11.el8 | 0:0.2.5-3.rhaos4.11.el8 |
redhat/skopeo | <2:1.5.2-3.rhaos4.11.el8 | 2:1.5.2-3.rhaos4.11.el8 |
redhat/slirp4netns | <0:1.1.8-1.rhaos4.11.el8 | 0:1.1.8-1.rhaos4.11.el8 |
redhat/toolbox | <0:0.0.9-1.rhaos4.11.el8 | 0:0.0.9-1.rhaos4.11.el8 |
redhat/cri-o | <0:1.24.3-6.rhaos4.11.gitc4567c0.el8 | 0:1.24.3-6.rhaos4.11.gitc4567c0.el8 |
redhat/cri-tools | <0:1.24.2-7.el8 | 0:1.24.2-7.el8 |
redhat/butane | <0:0.16.0-2.rhaos4.12.el8 | 0:0.16.0-2.rhaos4.12.el8 |
redhat/ignition | <0:2.14.0-5.rhaos4.12.el8 | 0:2.14.0-5.rhaos4.12.el8 |
redhat/etcd | <0:3.3.23-12.el8 | 0:3.3.23-12.el8 |
redhat/kubevirt | <0:4.12.0-1057.el7 | 0:4.12.0-1057.el7 |
redhat/kubevirt | <0:4.12.0-1057.el8 | 0:4.12.0-1057.el8 |
redhat/golang | <1.18.4 | 1.18.4 |
redhat/golang | <1.17.12 | 1.17.12 |
debian/golang-1.15 | <=1.15.15-1~deb11u4 | |
debian/golang-1.19 | 1.19.8-2 | |
IBM Concert Software | <=1.0.0 - 1.0.1 | |
Go (Golang) language by Google | <1.17.12 | |
Go (Golang) language by Google | >=1.18.0<1.18.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)