GHSA-jj45-xvq5-rhh9

Suggest an improvement
Source
https://github.com/advisories/GHSA-jj45-xvq5-rhh9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jj45-xvq5-rhh9/GHSA-jj45-xvq5-rhh9.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jj45-xvq5-rhh9
Aliases
Downstream
CGA (28)
Published
2026-04-25T21:30:22Z
Modified
2026-07-24T19:26:25Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Kratos has a Confused Deputy issue
Details

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue.

Database specific
{
    "cwe_ids": [
        "CWE-441"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-05T20:24:19Z",
    "nvd_published_at": "2026-04-25T19:16:00Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/go-kratos/kratos/v2

Package

Name
github.com/go-kratos/kratos/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/go-kratos/kratos/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.9.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-jj45-xvq5-rhh9/GHSA-jj45-xvq5-rhh9.json"