VDB
GO-2025-3683
GO-2025-3683
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf
Risk Scores
CVSS v4.0
5.099999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | justinas/nosurf | 0, 0 |
Timeline
- May 15, 2025 CVE Published
- Jun 12, 2025 CVE Updated
References
- https://github.com/justinas/nosurf/security/advisories/GHSA-w9hf-35q4-vcjw advisory
- https://github.com/justinas/nosurf/commit/ec9bb776d8e5ba9e906b6eb70428f4e7b009feee patch
- https://github.com/advisories/GHSA-rq77-p4h8-4crw url
- https://github.com/justinas/nosurf-cve-2025-46721 url
- https://github.com/justinas/nosurf/releases/tag/v1.2.0 url