Bug 2384089 (GO-2025-3770) - github.com/go-chi/chi: Host Header Injection in github.com/go-chi/chi
Summary: github.com/go-chi/chi: Host Header Injection in github.com/go-chi/chi
Keywords:
Status: NEW
Alias: GO-2025-3770
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2384103 2384104 2384106 2384122 2384123 2384124 2384125 2384126 2384127 2384128 2384129 2384102 2384105 2384107 2384108 2384109 2384110 2384111 2384112 2384113 2384114 2384115 2384116 2384117 2384118 2384119 2384120 2384121 2384130 2384131 2384132
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-28 21:01 UTC by OSIDB Bzimport
Modified: 2025-09-15 08:29 UTC (History)
79 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-07-28 21:01:58 UTC
Host Header Injection which Leads to Open Redirect in RedirectSlashes in github.com/go-chi/chi


Note You need to log in before you can comment on or make changes to this bug.