CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.
CVE
CVE-2025-22871
Severity
CRITICAL
CVSS
9.1
EPSS
0.78%
Original NVD Description
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.