Reflected XSS in go-httpbin due to unrestricted client control over Content-Type in github.com/mccutchen/go-httpbin
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3554" }