Security Advisory

CVE-2022-26945

9.8
CRITICAL

Vulnerability Description

go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
Published Date May 25, 2022
Official Source NIST NVD Advisory