汇总 gohttp_project 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
常见弱点模式包括 缓冲区溢出与内存损坏,在 生产负载与软件部署 使用场景中可能带来 应用崩溃与内存损坏 等风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2019-12198 | In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header. | [email protected] | 7.5 | 1.27% | 2019-05-20 | 2026-06-16 |
| CVE-2019-12160 | GoHTTP through 2017-07-25 has a sendHeader use-after-free. | [email protected] | 9.8 | 1.66% | 2019-05-17 | 2026-06-16 |
| CVE-2019-12159 | GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via a long URL. | [email protected] | 7.5 | 1.34% | 2019-05-17 | 2026-06-16 |
| CVE-2019-12158 | GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension. | [email protected] | 9.8 | 1.57% | 2019-05-17 | 2026-06-16 |