The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| spiral/roadrunner(Packagist) | 0 | 2025.1.0 | N/A |
CVSS Metrics