Vulnerability GO-2026-6566

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
v1.6.6 - v1.7.1
v1.6.6 - v1.7.1

Summary

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio

Details

Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio

Impacted packages

Timeline

Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC