{"id":"CVE-2024-45258","aliases":["GHSA-cj55-gc7m-wvcq","GO-2024-3098"],"url":"https://o3.security/vulnerability/CVE-2024-45258","summary":"req may send an unintended request when a malformed URL is provided","details":"The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a \"garbage in, garbage out\" design.","published":"2024-08-25T00:00:00Z","modified":"2026-07-15T01:48:52.291890254Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/imroc/req/v3","fixedVersion":"3.43.4"},{"ecosystem":"Go","name":"github.com/imroc/req","fixedVersion":"3.43.4"},{"ecosystem":"Go","name":"github.com/imroc/req/v2","fixedVersion":"3.43.4"}],"fix":{"url":"https://github.com/imroc/req/commit/04e3ece5b380ecad9da3551c449f1b8a9aa76d3d","label":"imroc/req@04e3ece"},"references":[{"type":"WEB","url":"https://github.com/imroc/req/compare/v3.43.3...v3.43.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45258.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45258"},{"type":"FIX","url":"https://github.com/imroc/req/commit/04e3ece5b380ecad9da3551c449f1b8a9aa76d3d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:52.291890254Z"}}