The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers…
Go·CWE-436·Published 2023-07-11