Source: golang-1.25
Version: 1.25.0-2
Severity: grave
Tags: security upstream
Forwarded: https://github.com/golang/go/issues/75054
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for golang-1.25.

CVE-2025-47910[0]:
| When using http.CrossOriginProtection, the AddInsecureBypassPattern
| method can unexpectedly bypass more requests than intended.
| CrossOriginProtection then skips validation, but forwards the
| original request path, which may be served by a different handler
| without the intended security protections.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-47910
    https://www.cve.org/CVERecord?id=CVE-2025-47910
[1] https://github.com/golang/go/issues/75054
[2] https://groups.google.com/g/golang-announce/c/PtW9VW21NPs/m/DJhMQ-m5AQAJ

Regards,
Salvatore

Reply via email to