VDB

CVE-2025-47910

CVE-2025-47910 PUBLISHED CVSS 5.400000095367432 MEDIUM

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

EPSS 0.33% · 25.5th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.33%
25.5th percentile

Affected Products

VendorProductVersions
Bitnamigolang1.25.0
Bitnamigolang1.25.0

Timeline

  • Sep 3, 2025 CVE Published
  • Sep 23, 2025 EPSS Score
  • Sep 30, 2025 EPSS Score
  • Oct 4, 2025 Coalition ESS Score
  • Oct 6, 2025 Coalition ESS Score
  • Oct 7, 2025 EPSS Score
  • Oct 14, 2025 EPSS Score
  • Oct 21, 2025 EPSS Score
  • Oct 28, 2025 EPSS Score
  • Nov 4, 2025 EPSS Score
  • Nov 11, 2025 EPSS Score
  • Nov 16, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›