CVE-2026-94439: HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http

Published Oct 8, 2026
·
Updated

When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.

Affected Software

1 affected component
go net/http

Event History

Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to request smuggling risk?

The relevant scenario is an HTTP/1 connection with an intermediate proxy that treats data after a successful CONNECT response as tunneled while the Go net/http server continues interpreting that data as HTTP requests.

2

What does an attacker need to trigger the issue?

The server must have a handler that returns a 2xx response to an HTTP/1 CONNECT request and then returns without hijacking the connection. Exploitation also depends on the mismatched interpretation of the connection between the proxy and server.

3

Is this behavior expected after a successful HTTP/1 CONNECT response?

No. A 2xx response to an HTTP/1 CONNECT request converts the connection into a tunnel, so the server should not continue reading it as an HTTP connection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203