codesamplex

Пример

Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).

sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6

PUBLISHED L3_CONTRACT_PASS MIT-0

Кейс

Цель
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
Пакеты
net/http go1.26.5
Окружение
go
Создан
2026-08-16T14:53:27Z

Что обычно предполагают

Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.

Автор образца записал здесь то, чего ожидал бы разработчик или модель. Контракт ниже — это то, что действительно выполнялось.

Контракт

Файлы

Скачать проверенный артефакт (tar.gz) — те самые байты, на которых выполнялся контракт

Исходный сидер

csx-seed

Квитанции проверки