Bug 2441027 (CVE-2025-69725)

Summary: CVE-2025-69725 go-chi/chi: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abuckta, adudiak, akoudelk, alcohan, anthomas, aprice, bdettelb, caswilli, cmah, crizzo, dfreiber, dhanak, dkuc, doconnor, drosa, drow, dsimansk, ehelms, ggainey, gparvin, gtanzill, jbalunas, jburrell, jbuscemi, jcantril, jdobes, jkoehler, jmitchel, jsamir, jsherril, juwatts, jvasik, kaycoth, kgaikwad, kingland, kshier, kverlaen, lball, lbragsta, lphiri, mhulan, mnovotny, mstipich, mwringe, ngough, nmoumoul, oezr, orabin, osousa, pahickey, pbohmill, pcreech, rblanco, rchan, rexwhite, rhaigner, rochandr, rojacob, sausingh, smallamp, stcannon, sthirugn, teagle, tmalecek, veshanka, vkumar, vmugicag, wenshen, xiyuan, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in go-chi/chi, a Go (programming language) HTTP router. This open redirect vulnerability, specifically within the RedirectSlashes function, allows a remote attacker to redirect users to malicious websites. This occurs by manipulating the legitimate website's domain, potentially leading to phishing attacks or other forms of social engineering.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2441149, 2441150, 2441151, 2441152, 2441153, 2441154, 2441155, 2441156, 2441157, 2441158, 2441159, 2441160, 2441161, 2441162, 2441163, 2441164, 2441165, 2441166, 2441168, 2441169, 2441170, 2441171, 2441172, 2441173, 2441174, 2441175, 2441176, 2441177, 2441178, 2441179, 2441180, 2441181, 2441182    
Bug Blocks:    

Description OSIDB Bzimport 2026-02-19 17:04:26 UTC
An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.