Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69725

Опубликовано: 19 фев. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

A flaw was found in go-chi/chi, a Go (programming language) HTTP router. This open redirect vulnerability, specifically within the RedirectSlashes function, allows a remote attacker to redirect users to malicious websites. This occurs by manipulating the legitimate website's domain, potentially leading to phishing attacks or other forms of social engineering.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleFix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2441027go-chi/chi: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites

EPSS

Процентиль: 12%
0.00215
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
6 месяцев назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

CVSS3: 4.7
nvd
6 месяцев назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

CVSS3: 4.7
debian
6 месяцев назад

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlash ...

CVSS3: 4.7
github
7 месяцев назад

chi has an open redirect vulnerability in the RedirectSlashes middleware

suse-cvrf
около 1 месяца назад

Security update for warewulf4

EPSS

Процентиль: 12%
0.00215
Низкий

4.7 Medium

CVSS3