GHSA-xcvf-46f4-xwxf

Suggest an improvement
Source
https://github.com/advisories/GHSA-xcvf-46f4-xwxf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-xcvf-46f4-xwxf/GHSA-xcvf-46f4-xwxf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-xcvf-46f4-xwxf
Downstream
CGA (164)
Withdrawn
2026-10-02T23:17:35Z
Published
2026-08-14T12:31:24Z
Modified
2026-10-02T23:30:04Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-vrw8-fxc6-2r93. This link is maintained to preserve external references.

Original Description

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-02T23:17:35Z",
    "nvd_published_at":  "2026-08-14T12:16:43Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/go-chi/chi

Package

Name
github.com/go-chi/chi
View open source insights on deps.dev
Purl
pkg:golang/github.com/go-chi/chi

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
5.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-xcvf-46f4-xwxf/GHSA-xcvf-46f4-xwxf.json"