RHSA-2025:8477: Moderate: golang security update
Moderate: golang security update
Other sources
The golang packages provide the Go programming language compiler.Security Fix(es): net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8477?
The severity of the RHSA-2025:8477 vulnerability is classified as moderate.
What does the RHSA-2025:8477 vulnerability affect?
The RHSA-2025:8477 vulnerability affects the Go programming language compiler packages provided in various Red Hat Enterprise Linux versions.
How do I fix RHSA-2025:8477?
To fix RHSA-2025:8477, update the golang and related packages to version 1.23.9-1.el10_0.
What is CVE-2025-22871 related to RHSA-2025:8477?
CVE-2025-22871 is the specific identifier for the request smuggling vulnerability addressed in RHSA-2025:8477.
What are the risks of not addressing RHSA-2025:8477?
Not addressing RHSA-2025:8477 could potentially expose applications to exploitation via request smuggling attacks.