VDB

GO-2024-2955

GO-2024-2955 PUBLISHED

Gin-Gonic CORS middleware mishandles a wildcard at the end of an origin string. Examples: https://example.community/* is accepted by the origin string https://example.com/* and http://localhost.example.com/* is accepted by the origin string http://localhost/* .

Affected Products

VendorProductVersions
github.comgin-contrib/cors0, 0

Timeline

  • Jul 2, 2024 CVE Published
  • Jul 2, 2024 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›