๐Ÿ” CVE Alert

CVE-2025-71405

UNKNOWN 0.0

go-chi chi before v5.2.2 Open Redirect via RedirectSlashes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.

CWE CWE-601
Vendor go-chi
Product chi
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for go-chi chi

Be the first to know when new unknown vulnerabilities affecting go-chi chi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

go-chi / chi
0 < 5.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93 vulncheck.com: https://www.vulncheck.com/advisories/go-chi-chi-before-open-redirect-via-redirectslashes

Credits

๐Ÿ” anuraagbaishya