alpine · CVE-2025-22871

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2025-22871: 1 source package rows (go); 3 state rows across 3 repos (3.21-community, 3.22-community, edge-community); fixed 3, open 0.

Description:

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

cvelogic Threat Intelligence