Answer in brief
CVE-2026-94439 records a Unknown severity vulnerability in HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http. The current sources do not mark it as known exploited. The current feed maps Go standard library/net/http (generic), stdlib (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Go standard library/net/http (generic), stdlib (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Go standard library/net/httpgeneric | >=0 <1.26.9 || >=1.27.0-0 <1.27.2 | 1.26.9, 1.27.2 |
| stdlibgo | >=0 <1.26.9 >=1.27.0-0 <1.27.2 | 1.26.9, 1.27.2 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP.
Quoted source text, attributed separately from HOL analysis.