{"id":"CVE-2022-26945","aliases":["CVE-2022-30321","CVE-2022-30322","CVE-2022-30323","GHSA-28r2-q6m8-9hpx","GHSA-cjr4-fv6c-f3mv","GHSA-fcgg-rvwg-jv58","GHSA-x24g-9w7v-vprh","GO-2022-0586"],"url":"https://o3.security/vulnerability/CVE-2022-26945","summary":"HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion","details":"go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.","published":"2022-05-25T11:19:48Z","modified":"2026-07-15T01:49:02.286497010Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hashicorp/go-getter","fixedVersion":"1.6.1"},{"ecosystem":"Go","name":"github.com/hashicorp/go-getter","fixedVersion":"2.1.0"},{"ecosystem":"Go","name":"github.com/hashicorp/go-getter/v2","fixedVersion":"2.1.0"},{"ecosystem":"Go","name":"github.com/hashicorp/go-getter/s3/v2","fixedVersion":"2.1.0"},{"ecosystem":"Go","name":"github.com/hashicorp/go-getter/gcs/v2","fixedVersion":"2.1.0"}],"fix":null,"references":[{"type":"WEB","url":"https://discuss.hashicorp.com"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2022-13-multiple-vulnerabilities-in-go-getter-library/39930"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26945.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26945"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.286497010Z"}}