Bug 2384089 (GO-2025-3770)

Summary: github.com/go-chi/chi: Host Header Injection in github.com/go-chi/chi
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aarif, adudiak, agarcial, alcohan, aoconnor, aprice, asegurap, bdettelb, brainfor, caswilli, cmah, crizzo, dbosanac, dfreiber, dhanak, dkuc, dnakabaa, doconnor, drosa, drow, dsimansk, fjansen, gparvin, gtanzill, jburrell, jbuscemi, jcantril, jdobes, jkoehler, jmitchel, jreimann, jsamir, jsherril, jvasik, kaycoth, kgaikwad, kholdawa, kingland, kshier, kverlaen, lball, lcouzens, ldai, ljawale, lphiri, lsharar, lucarval, luizcosta, matzew, mdessi, mnovotny, mpierce, mrizzi, mskarbek, mwringe, ngough, njean, nweather, oezr, omaciel, orabin, owatkins, pahickey, pcattana, periklis, rblanco, rbobbitt, rhaigner, rochandr, rojacob, sausingh, stcannon, sthirugn, teagle, veshanka, vkrizan, vkumar, vmugicag, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A header injection flaw has been discovered in the github.com/go-chi/chi go library. This flaw allows host headers to be manipulated by a user to be any arbitrary host. This leads to open redirect when using the RedirectSlashes middleware though it cannot be exploited from browsers or email clients.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2384103, 2384104, 2384106, 2384122, 2384123, 2384124, 2384125, 2384126, 2384127, 2384128, 2384129, 2384102, 2384105, 2384107, 2384108, 2384109, 2384110, 2384111, 2384112, 2384113, 2384114, 2384115, 2384116, 2384117, 2384118, 2384119, 2384120, 2384121, 2384130, 2384131, 2384132    
Bug Blocks:    

Description OSIDB Bzimport 2025-07-28 21:01:58 UTC
Host Header Injection which Leads to Open Redirect in RedirectSlashes in github.com/go-chi/chi