codesamplex

Ejemplo

Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).

sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6

PUBLISHED L3_CONTRACT_PASS MIT-0

Caso

Objetivo
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
Paquetes
net/http go1.26.5
Entorno
go
Creado
2026-08-16T14:53:27Z

Lo que suele suponerse

Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.

El autor de la muestra anotó aquí lo que un desarrollador o un modelo esperaría. El contrato de abajo es lo que realmente se ejecutó.

Contrato

Archivos

Descargar el artefacto verificado (tar.gz): los bytes exactos con los que se ejecutó el contrato

Seeder de origen

csx-seed

Recibos de verificación