A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-04-04T14:46:17.808Z
Reserved: 2022-09-28T17:00:06.609Z
Link: CVE-2022-41721

Updated: 2024-08-03T12:49:43.550Z

Status : Modified
Published: 2023-01-13T23:15:09.250
Modified: 2025-04-04T15:15:43.490
Link: CVE-2022-41721
