PT-2025-2689 · Google+11 · Google Go+11

Kyle Seely

·

Published

2025-01-16

·

Updated

2026-02-18

·

CVE-2024-45336

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Go versions prior to 1.22.10 and 1.23.4
Description The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. However, in the event that the client received a subsequent same-domain redirect, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.
Recommendations For Google Go versions prior to 1.22.10, update to version 1.22.10 or later to resolve the issue. For Google Go versions prior to 1.23.4, update to version 1.23.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of cross-domain redirects to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:3772
ALSA-2025:7466
ALSA-2025:7592
ALT-PU-2025-1484
ALT-PU-2025-1742
ALT-PU-2025-1744
AZL-55998
AZL-56005
AZL-56058
AZL-78950
BDU:2025-02667
BIT-GOLANG-2024-45336
CESA-2025_3772
CLEANSTART-2026-CR41732
CLEANSTART-2026-OJ41940
CVE-2024-45336
ECHO-BEFE-522F-1557
GO-2025-3420
INFSA-2025_3335
INFSA-2025_3772
MGASA-2025-0021
OESA-2025-1221
OESA-2025-1222
OESA-2025-1223
OESA-2025-1224
OPENSUSE-SU-2025:14693-1
OPENSUSE-SU-2025:14694-1
OPENSUSE-SU-2025:14695-1
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025:15030-1
OPENSUSE-SU-2025_0280-1
OPENSUSE-SU-2025_0281-1
OPENSUSE-SU-2025_0285-1
OPENSUSE-SU-2025_0297-1
OPENSUSE-SU-2025_0429-1
RHSA-2025:3335
RHSA-2025:3593
RHSA-2025:3772
RHSA-2025:3773
RHSA-2025:7326
RHSA-2025:7466
RHSA-2025:7592
RHSA-2025:7624
RHSA-2025:9514
RHSA-2025_3335
RHSA-2025_3772
RHSA-2025_3773
RHSA-2025_7326
SUSE-SU-2025:01731-1
SUSE-SU-2025:0280-1
SUSE-SU-2025:0281-1
SUSE-SU-2025:0285-1
SUSE-SU-2025:0297-1
SUSE-SU-2025:03159-1
SUSE-SU-2025:0429-1
SUSE-SU-2025:1555-1
SUSE-SU-2025_01731-1
SUSE-SU-2025_0280-1
SUSE-SU-2025_0281-1
SUSE-SU-2025_0285-1
SUSE-SU-2025_03159-1
SUSE-SU-2025_1555-1
USN-7574-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Google Go
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu