Vulnerability Report: GO-2025-3683
- CVE-2025-46721, GHSA-w9hf-35q4-vcjw
- Affects: github.com/justinas/nosurf
- Published: May 15, 2025
- Modified: Jun 12, 2025
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf
For detailed information about this vulnerability, visit https://github.com/justinas/nosurf/security/advisories/GHSA-w9hf-35q4-vcjw.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.2.0
Aliases
References
- https://github.com/justinas/nosurf/security/advisories/GHSA-w9hf-35q4-vcjw
- https://github.com/justinas/nosurf/commit/ec9bb776d8e5ba9e906b6eb70428f4e7b009feee
- https://github.com/advisories/GHSA-rq77-p4h8-4crw
- https://github.com/justinas/nosurf-cve-2025-46721
- https://github.com/justinas/nosurf/releases/tag/v1.2.0
- https://vuln.go.dev/ID/GO-2025-3683.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.