Answer in brief
CVE-2026-56866 records a Unknown severity vulnerability in HTTP/1 client connection desynchronization after CONNECT rejection in net/http. The current sources do not mark it as known exploited. The current feed maps Go standard library/net/http (generic), Go standard library/net/http/httputil (generic), stdlib (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Go standard library/net/http (generic), Go standard library/net/http/httputil (generic), stdlib (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Go standard library/net/httpgeneric | >=0 <1.26.9 || >=1.27.0-0 <1.27.2 | 1.26.9, 1.27.2 |
| Go standard library/net/http/httputilgeneric | >=0 <1.26.9 || >=1.27.0-0 <1.27.2 | 1.26.9, 1.27.2 |
| stdlibgo | >=0 <1.26.9 >=1.27.0-0 <1.27.2 | 1.26.9, 1.27.2 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning.
Quoted source text, attributed separately from HOL analysis.