Skip to main content

CVE-2025-22871

CVE Details

Visit the official vulnerability details page for CVE-2025-22871 to learn more.

Initial Publication

04/08/2025

Last Update

04/18/2025

Third Party Dependency

go

NIST CVE Summary

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

CVE Severity

9.1

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.