CVE-2026-21697

CVSS

No CVSS.

a

xios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execution without synchronization, directly modifying the shared `http.Client`'s `Transport`, `Timeout`, and `CheckRedirect` properties. Impacted applications include that that use axios4go with concurrent requests (multiple goroutines, `GetAsync`, `PostAsync`, etc.), those where different requests use different proxy configurations, and those that handle sensitive data (authentication credentials, tokens, API keys). Version 0.6.4 fixes this issue.

Configurations

No configuration.

History

07 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-07 23:15

Updated : 2026-01-08 18:08


NVD link : CVE-2026-21697

Mitre link : CVE-2026-21697

CVE.ORG link : CVE-2026-21697


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')