Vulnerability GO-2026-6566
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
v1.6.6 - v1.7.1
v1.6.6 - v1.7.1
Summary
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
Details
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 days ago
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
v1.6.6 - v1.7.1 GHSA-fq95-v8xc-jm3v
v1.6.6 - v1.7.1 GHSA-fq95-v8xc-jm3v
Unknown
1 year ago
Fabio allows HTTP clients to manipulate custom headers it adds in github.com/fabiolb/fabio
v1.0.0 - v1.6.5 GO-2025-3722
v1.0.0 - v1.6.5 GO-2025-3722
Critical
1 year ago
Fabio allows HTTP clients to manipulate custom headers it adds
v1.0.0 - v1.6.5 GHSA-q7p4-7xjv-j3wf
v1.0.0 - v1.6.5 GHSA-q7p4-7xjv-j3wf
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC