Get real-time updates on Telegram
Verified
CVE-2026-56866: net/http 0 to before 1.26.9, 1.27.0-0 to before 1.27.2; +1 more affected products
Affected technology
net/http · 0 to before 1.26.9, 1.27.0-0 to before 1.27.2
Go standard library
net/http/httputil · 0 to before 1.26.9, 1.27.0-0 to before 1.27.2
Go standard library
Component: Not specified by the source
Function: persistConn.readLoop, Client.CloseIdleConnections, Client.Do, Client.Get, Client.Head, Client.Post, Client.PostForm, ClientConn.Close, ClientConn.RoundTrip, Get, Head, Post, PostForm, Transport.CloseIdleConnections, Transport.NewClientConn, Transport.RoundTrip, http1ClientConn.Close, http1ClientConn.RoundTrip, ReverseProxy.ServeHTTP, DumpRequestOut
What an attacker can do
The source does not specify what an attacker can achieve.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 03:17:07.463462+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-56866.html