{"id":"CVE-2022-41721","title":"x/net/http2/h2c: request smuggling (CVE-2022-41721)","summary":"A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-444","vendor":"Red Hat","product":"OpenShift Service Mesh 2.1","affected":["openshift_serverless","openshift_service_mesh 2.1","openshift_service_mesh 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 3","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4","openshift_dev_spaces","openshift_container_platform 4.13","mta_6_2_for_rhel 8"],"patched":["openshift_container_platform 4.13","mta_6_2_for_rhel 8"],"published":"2023-01-13","updated":"2026-09-17","sourceUpdated":"2026-09-17T13:32:35+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41721.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41721.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-41721"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2162182"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-41721"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41721"},{"url":"https://go.dev/cl/447396"},{"url":"https://go.dev/issue/56352"},{"url":"https://pkg.go.dev/vuln/GO-2023-1495"},{"url":"https://access.redhat.com/errata/RHSA-2023:1326"},{"url":"https://access.redhat.com/errata/RHSA-2023:4627"},{"url":"https://cs.opensource.google/go/x/net"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X3H3EWQXM2XL5AGBX6UL443JEJ3GQXJN"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X5DXTLLWN6HKI5I35EUZRBISTNZJ75GP"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.01814,"epssPercentile":0.77753,"aliases":["GHSA-fxg5-wq6x-vr4w","GO-2023-1495"],"ecosystem":"go","ingestedAt":"2026-08-07T19:14:16.960Z","slug":"CVE-2022-41721","body":"## Overview\n\nA request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.\n\n## Vendor advisories\n\n- **RHSA-2023:1326** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2023-05-17 · [advisory](https://access.redhat.com/errata/RHSA-2023:1326)\n- **RHSA-2023:4627** · Red Hat · fixed in: MTA 6.2 for RHEL 8 · released 2023-08-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:4627)\n- **Red Hat VEX** · Moderate · affected: OpenShift Serverless, OpenShift Service Mesh 2.1, OpenShift Service Mesh 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Security 3, Red Hat Enterprise Linux 8, … · no fix planned: OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Security 3, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-41721.json)\n\n**x/net/http2/h2c: request smuggling** — rated Moderate by Red Hat. Released 2022-01-01, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Serverless\n- OpenShift Service Mesh 2.1\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 3\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Spaces\n\nFixed:\n\n- Red Hat OpenShift Container Platform 4.13\n- MTA 6.2 for RHEL 8\n\nNo fix planned:\n\n- OpenShift Service Mesh 2.1\n- Red Hat Advanced Cluster Security 3\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat OpenShift Dev Spaces\n\nNot affected:\n\n- MTA 6.2 for RHEL 8\n- Red Hat OpenShift Container Platform 4.13\n- OpenShift Pipelines\n- Red Hat Advanced Cluster Security 3\n\n## Remediation\n\nFor OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html\n\nYou may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at\nhttps://quay.io/repository/openshift-release-dev/ocp-release?tab=tags\n\nThe sha values for the release are:\n\n(For x8… https://access.redhat.com/errata/RHSA-2023:1326\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:4627\n\n## Package advisory (CVE-2022-41721)\n\nAffected packages:\n\n- `golang.org/x/net >= 0.0.0-20220524220425-1d687d428aca, < 0.1.1-0.20221104162952-702349b0e862`\n\nPatched in:\n\n- `golang.org/x/net 0.1.1-0.20221104162952-702349b0e862`\n\nSource: https://osv.dev/vulnerability/GHSA-fxg5-wq6x-vr4w","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}