Back to search
CVE-2025-47910
Published: Sep 22, 2025
Modified: Sep 24, 2025
PUBLISHED
Description
When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.
| Vendor | Product | Versions |
|---|---|---|
Go standard library | net/http | affected 1.25.0 - < 1.25.1 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now