Back

CRITICAL

github.com/gin-contrib/cors: Gin mishandles a wildcard in the origin string in github.com/gin-contrib/cors

Published Jun 28, 2024

Description

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 28, 2024
Updated Nov 3, 2025
Reserved Jun 28, 2024
CISA Vulnrichment
Updated Jul 9, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 2, 2024
GHSA-869C-J7WC-8JQV