{"id":"CVE-2019-9741","details":"An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \\r\\n followed by an HTTP header or a Redis command.","modified":"2026-07-07T08:50:16.120739832Z","published":"2019-03-13T08:29:00.553Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"29"},{"last_affected":"29"}],"source":"CPE_STRING"},{"source":"CPE_STRING","vendor_product":"redhat:developer_tools","cpes":["cpe:2.3:a:redhat:developer_tools:1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"}]},{"vendor_product":"redhat:enterprise_linux","cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOOVCEPQM7TZA6VEZEEB7QZABXNHQEHH/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/107432"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1300"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1519"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00007.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html"},{"type":"FIX","url":"https://github.com/golang/go/issues/30794"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/golang/go","events":[{"introduced":"35bb62e60a7779ff82c3067903b3306ff8666471"},{"last_affected":"35bb62e60a7779ff82c3067903b3306ff8666471"}],"database_specific":{"cpe":"cpe:2.3:a:golang:go:1.11.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.11.5"},{"last_affected":"1.11.5"}],"source":"CPE_STRING"}}],"versions":["1.11.5","go1.11.5"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9741.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}