Overview
A flaw was found in the net/http/httputil package, specifically within the ReverseProxy component. This vulnerability allows the ReverseProxy to forward query parameters that are not visible to Rewrite functions. This occurs because the ReverseProxy does not correctly consider the url.ParseQuery limit on the total number of query parameters. A remote attacker could exploit this to send hidden query parameters, potentially bypassing security policies or controls implemented by Rewrite functions, leading to information disclosure or unexpected behavior.
Vendor advisories
- RHSA-2026:49702 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-08-03 · advisory
- RHSA-2026:22120 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-01 · advisory
- RHSA-2026:22112 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-06-01 · advisory
- RHSA-2026:61253 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-08-31 · advisory
- RHSA-2026:57649 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-08-20 · advisory
- RHSA-2026:49712 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-08-03 · advisory
- RHSA-2026:22121 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-01 · advisory
- RHSA-2026:43692 · Red Hat · fixed in: OpenShift API for Data Protection 1.6 · released 2026-07-22 · advisory
- RHSA-2026:23262 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · advisory
- RHSA-2026:23264 · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-04 · advisory
- RHSA-2026:63096 · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-09-08 · advisory
- Red Hat VEX · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, Cryostat 4, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, … · updated 2026-09-23 · vex
- RHSA-2026:57194 · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · advisory
net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — rated Moderate by Red Hat. Released 2026-05-07, updated 2026-09-23.
Affected:
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Custom Metric Autoscaler operator for Red Hat Openshift
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- Fence Agents Remediation Operator
- File Integrity Operator
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 3
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
- Red Hat Connectivity Link 1
- Red Hat Developer Hub
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
Fixed:
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- OpenShift API for Data Protection 1.6
- Red Hat Hardened Images
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4
- multicluster engine for Kubernetes 2.11
No fix planned:
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Custom Metric Autoscaler operator for Red Hat Openshift
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- Fence Agents Remediation Operator
- File Integrity Operator
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 3
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 9
- Red Hat Certification Program for Red Hat Enterprise Linux 9
- Red Hat Connectivity Link 1
- Red Hat Developer Hub
- Red Hat Edge Manager 1
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
Not affected:
- OpenShift API for Data Protection 1.6
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenShift Service Mesh 3.0
- Red Hat OpenShift Service Mesh 3.1
- Red Hat OpenShift Service Mesh 3.2
- Red Hat OpenShift Service Mesh 3.3
- Red Hat OpenShift Service Mesh 3.4
- multicluster engine for Kubernetes 2.11
Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:49702
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22120
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:22112
Workarounds / mitigations:
- Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable
urlmaxqueryparams to a higher value (e.g., GODEBUG=urlmaxqueryparams=20000), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering.
Package advisory (CVE-2026-39825)
Affected packages:
stdlib >= 1.26.0-0, < 1.26.3
Patched in:
Source: https://osv.dev/vulnerability/GO-2026-4976