Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-47910

Опубликовано: 22 сент. 2025
Источник: debian

Описание

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.25fixed1.25.1-1package
golang-1.24not-affectedpackage
golang-1.23not-affectedpackage
golang-1.19not-affectedpackage
golang-1.15not-affectedpackage

Примечания

  • https://groups.google.com/g/golang-announce/c/PtW9VW21NPs/m/DJhMQ-m5AQAJ

  • https://go-review.googlesource.com/c/go/+/699275

  • https://github.com/golang/go/issues/75054

  • Introduced after: https://github.com/golang/go/commit/1881d680b0b573c32d3002c37902760668ffec0f (go1.25rc1)

  • Fixed by: https://github.com/golang/go/commit/b1959cf6f7673eaffa89bbdb00e68b30cde3aa8a (go1.25.1)

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

CVSS3: 5.4
nvd
4 месяца назад

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

suse-cvrf
3 месяца назад

Security update for go1.25-openssl

suse-cvrf
3 месяца назад

Security update for go1.25-openssl

suse-cvrf
4 месяца назад

Security update for go1.25