VDB

GO-2025-3751

GO-2025-3751 PUBLISHED CVSS 8.699999809265137 HIGH

Sensitive headers not cleared on cross-origin redirect in net/http

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
wolficert-manager-cmctl0, 0, 0
chainguardprometheus-node-exporter-1.40, 0
chainguards5cmd0, 0
chainguardpromxy0, 0
chainguardaws-flb-kinesis-fips0, 0
chainguardhelm-40
chainguardkubernetes-csi-livenessprobe-fips-2.100, 0
chainguardvelero-plugin-for-microsoft-azure-fips0, 0
wolfistern0, 0, 0
chainguardrekor0, 0
chainguardsftpgo-plugin-eventstore0, 0
wolfidelve0, 0, 0
chainguardbeats-70, 0
chainguarddapr-1.140
chainguardvendir0, 0
chainguarddgraph0
chainguarddoppler-kubernetes-operator0
chainguardpetname0, 0
chainguardgcp-compute-persistent-disk-csi-driver-1.120
chainguardtimestamp-authority-fips0, 0

…and 1206 more

Timeline

  • Jun 11, 2025 CVE Published
  • Feb 17, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›