<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 08:36:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352859</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352859</link>
      <description>EUVD-2026-352859</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352859</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71405</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71405</link>
      <description>&lt;p&gt;chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71405</guid>
    </item>
    <item>
      <title>GHSA-vrw8-fxc6-2r93 — chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vrw8-fxc6-2r93</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-chi/chi/v5&lt;/p&gt;
&lt;p&gt;### Summary
The RedirectSlashes function in middleware/strip.go is vulnerable to host header injection which leads to open redirect.&lt;/p&gt;
&lt;p&gt;We consider this a **lower-severity** open redirect, as it can&amp;#39;t be exploited from browsers or email clients (requires manipulation of a Host header).&lt;/p&gt;
&lt;p&gt;### Details
The RedirectSlashes method uses the Host header to construct the redirectURL at this line https://github.com/go-chi/chi/blob/master/middleware/strip.go#L55&lt;/p&gt;
&lt;p&gt;The Host header can be manipulated by a user to be any arbitrary host. This leads to open redirect when using the RedirectSlashes middleware&lt;/p&gt;
&lt;p&gt;### PoC
Create a simple server which uses the RedirectSlashes middleware
```
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/go-chi/chi/v5&amp;#34;
	&amp;#34;github.com/go-chi/chi/v5/middleware&amp;#34; // Import the middleware package
)&lt;/p&gt;
&lt;p&gt;func main() {
	// Create a new Chi router
	r := chi.NewRouter()&lt;/p&gt;
&lt;p&gt;// Use the built-in RedirectSlashes middleware
	r.Use(middleware.RedirectSlashes) // Use middleware.RedirectSlashes&lt;/p&gt;
&lt;p&gt;// Define a route handler
	r.Get(&amp;#34;/&amp;#34;, func(w http.ResponseWriter, r *http.Request) {
		// A simple response
		w.Write([]byte(&amp;#34;Hello, World!&amp;#34;))
	})&lt;/p&gt;
&lt;p&gt;// Start the server
	fmt.Println(&amp;#34;Starting server on :8080&amp;#34;)
	http.ListenAndServe(&amp;#34;:8080&amp;#34;, r)
}
```
Run the server `go run main.go`&lt;/p&gt;
&lt;p&gt;Once the server is running, send a request that will trigger the RedirectSlashes function with an arbitrary Host header
`curl -iL -H &amp;#34;Host: example.com&amp;#34; http://localhost:8080/test/`&lt;/p&gt;
&lt;p&gt;Observe that the request will…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-chi/chi/v5&lt;/p&gt;
&lt;p&gt;### Summary
The RedirectSlashes function in middleware/strip.go is vulnerable to host header injection which leads to open redirect.&lt;/p&gt;
&lt;p&gt;We consider this a **lower-severity** open redirect, as it can&amp;#39;t be exploited from browsers or email clients (requires manipulation of a Host header).&lt;/p&gt;
&lt;p&gt;### Details
The RedirectSlashes method uses the Host header to construct the redirectURL at this line https://github.com/go-chi/chi/blob/master/middleware/strip.go#L55&lt;/p&gt;
&lt;p&gt;The Host header can be manipulated by a user to be any arbitrary host. This leads to open redirect when using the RedirectSlashes middleware&lt;/p&gt;
&lt;p&gt;### PoC
Create a simple server which uses the RedirectSlashes middleware
```
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/go-chi/chi/v5&amp;#34;
	&amp;#34;github.com/go-chi/chi/v5/middleware&amp;#34; // Import the middleware package
)&lt;/p&gt;
&lt;p&gt;func main() {
	// Create a new Chi router
	r := chi.NewRouter()&lt;/p&gt;
&lt;p&gt;// Use the built-in RedirectSlashes middleware
	r.Use(middleware.RedirectSlashes) // Use middleware.RedirectSlashes&lt;/p&gt;
&lt;p&gt;// Define a route handler
	r.Get(&amp;#34;/&amp;#34;, func(w http.ResponseWriter, r *http.Request) {
		// A simple response
		w.Write([]byte(&amp;#34;Hello, World!&amp;#34;))
	})&lt;/p&gt;
&lt;p&gt;// Start the server
	fmt.Println(&amp;#34;Starting server on :8080&amp;#34;)
	http.ListenAndServe(&amp;#34;:8080&amp;#34;, r)
}
```
Run the server `go run main.go`&lt;/p&gt;
&lt;p&gt;Once the server is running, send a request that will trigger the RedirectSlashes function with an arbitrary Host header
`curl -iL -H &amp;#34;Host: example.com&amp;#34; http://localhost:8080/test/`&lt;/p&gt;
&lt;p&gt;Observe that the request will…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vrw8-fxc6-2r93</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-71405</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71405</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-go-chi-chi, Ubuntu:24.04:LTS: golang-github-go-chi-chi, Ubuntu:26.04:LTS: golang-github-go-chi-chi&lt;/p&gt;
&lt;p&gt;chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-go-chi-chi, Ubuntu:24.04:LTS: golang-github-go-chi-chi, Ubuntu:26.04:LTS: golang-github-go-chi-chi&lt;/p&gt;
&lt;p&gt;chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71405</guid>
    </item>
  </channel>
</rss>
