CVE Vulnerabilities

CVE-2026-39825

Published: May 07, 2026 | Modified: May 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuerys limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query a1=x&a2=x&…&a10000=x&hidden=y can forward the parameter hidden=y while hiding it from the proxys Rewrite function.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.25.10 (excluding)
GoGolang1.26.0 (including)1.26.3 (excluding)
Golang-1.10Ubuntuesm-infra/xenial*
Golang-1.13Ubuntuesm-apps/xenial*
Golang-1.18Ubuntuesm-apps/xenial*
Golang-1.6Ubuntuesm-infra/xenial*

References