Gin-Gonic CORS middleware mishandles a wildcard at the end of an origin string. Examples: https://example.community/* is accepted by the origin string https://example.com/* and http://localhost.example.com/* is accepted by the origin string http://localhost/* .
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2955" }