{"id":"GO-2021-0143","details":"When a Handler does not explicitly set the Content-Type header,\nthe net/http/cgi and net/http/fcgi packages default to \"text/html\",\nwhich can cause a Cross-Site Scripting vulnerability if an attacker\ncan control any part of the contents of a response.\n","modified":"2022-05-13T18:33:00Z","published":"2022-02-17T18:15:47Z","withdrawn":"2024-05-15T05:37:11.077795Z","references":[{"type":"FIX","url":"https://go.dev/cl/252179"},{"type":"FIX","url":"https://go.googlesource.com/go/+/4f5cd0c0331943c7ec72df3b827d972584f77833"},{"type":"WEB","url":"https://go.dev/issue/40928"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/8wqlSbkLdPs"}],"affected":[{"package":{"name":"net/http/cgi","ecosystem":"Go","purl":"pkg:golang/net/http/cgi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.14.8"},{"introduced":"1.15.0"},{"fixed":"1.15.1"}]}],"ecosystem_specific":{"symbols":["response.Write"]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0143.json","url":"https://pkg.go.dev/vuln/GO-2021-0143"}},{"package":{"name":"net/http/fcgi","ecosystem":"Go","purl":"pkg:golang/net/http/fcgi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.14.8"},{"introduced":"1.15.0"},{"fixed":"1.15.1"}]}],"ecosystem_specific":{"symbols":["response.Write"]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0143.json","url":"https://pkg.go.dev/vuln/GO-2021-0143"}}],"schema_version":"1.7.3"}