codesamplex

示例

Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336).

sha256:ca2c5fb0a4c0366c9e1e2ca07cd75ca1c776ff2e9eab90fc258851b1d37fefe6

PUBLISHED L3_CONTRACT_PASS MIT-0

案例

目标
Prove that net/http keeps the Authorization header stripped through the full redirect chain after a cross-domain hop, and does not restore it on a subsequent same-domain redirect (CVE-2024-45336). HOW
net/http go1.26.5
环境
go
创建时间
2026-08-16T14:53:27Z

常见的想当然

Once net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.

这是本样本作者记下的、开发者或模型在此处通常会有的预期。下面的契约才是真正运行过的东西。

契约

文件

下载已验证的构件 (tar.gz) — 契约实际运行的那些字节

原始种子者

csx-seed

验证回执