VDB
CVE-2025-47910
CVE-2025-47910
PUBLISHED
CVSS 5.400000095367432 MEDIUM
When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.
EPSS 0.33% · 25.5th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.33%
25.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | golang | 1.25.0 |
| Bitnami | golang | 1.25.0 |
Timeline
- Sep 3, 2025 CVE Published
- Sep 23, 2025 EPSS Score
- Sep 30, 2025 EPSS Score
- Oct 4, 2025 Coalition ESS Score
- Oct 6, 2025 Coalition ESS Score
- Oct 7, 2025 EPSS Score
- Oct 14, 2025 EPSS Score
- Oct 21, 2025 EPSS Score
- Oct 28, 2025 EPSS Score
- Nov 4, 2025 EPSS Score
- Nov 11, 2025 EPSS Score
- Nov 16, 2025 Coalition ESS Score