codesamplex

Beispiel

Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).

sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6

PUBLISHED L3_CONTRACT_PASS MIT-0

Fall

Ziel
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
Pakete
net/http go1.26.5
Umgebung
go
Erstellt
2026-08-16T14:53:27Z

Häufige Annahme

Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.

So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.

Contract

Dateien

Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief

Ursprungs-Seeder

csx-seed

Verifizierungsbelege