github.com/valyala/fasthttp is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
40
Medium Risk
Affected versions of this package are vulnerable due to an off-by-one error in Content-Type header validation and insufficient blocking of dangerous headers (e.g., Set-Cookie and X-Forwarded-*) in HTTP trailers. Attackers could exploit this by injecting malicious trailers to bypass security controls, enabling session hijacking (via forced cookie adoption), redirect attacks (through injected Location headers), or IP spoofing (using X-Forwarded-For header) to mask their origin or trigger incorrect access decisions.
You are affected if you are using a version that falls within the vulnerable range.
github.com/valyala/fasthttp is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 1.32.0 - 1.64.0.
Upgrade the github.com/valyala/fasthttp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant