github.com/emicklei/go-restful/v3
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Jul 14, 2021
| Version | Released | |
|---|---|---|
v3.13.0
minor
|
v3.13.0
minor
|
|
v3.12.2
patch
|
v3.12.2
patch
|
|
v3.12.1
patch
|
v3.12.1
patch
|
|
v3.12.0
minor
|
v3.12.0
minor
|
|
v3.11.3
patch
|
v3.11.3
patch
|
|
v3.11.2
patch
|
v3.11.2
patch
|
|
v3.11.1
patch
|
v3.11.1
patch
|
|
v3.11.0
minor
|
v3.11.0
minor
|
|
v3.10.2
patch
|
v3.10.2
patch
|
|
v3.10.1
patch
|
v3.10.1
patch
|
|
v3.10.0
minor
|
v3.10.0
minor
|
|
v3.9.0
minor
|
v3.9.0
minor
|
|
v3.8.0
minor
|
v3.8.0
minor
|
|
v3.7.4
patch
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.4
patch
|
|
v3.7.3
patch
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.3
patch
|
|
v3.7.2
patch
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.2
patch
|
|
v3.7.1
patch
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.1
patch
|
|
v3.7.0
minor
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.7.0
minor
|
|
v3.6.0
minor
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.6.0
minor
|
|
v3.5.2
initial
1 CVE
CVE-2022-1996
GO-2022-0619
GHSA-r48q-9g5r-8q2h
Aug 15, 2022
Authorization bypass in github.com/emicklei/go-restful, go-restful/v2 and go-restful/v3 CORS filters that use an AllowedDomains configuration parameter can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is documented as a list of allowed origin domains, but values in this list are applied as regular expression matches. For example, an allowed domain of "example.com" will match the Origin header "example.com.malicious.domain". Fixed in
3.8.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v3.5.2
initial
|