github.com/gin-gonic/gin
Gin is a high-performance HTTP web framework written in Go. It provides a Martini-like API but with significantly better performance—up to 40 times faster—thanks to httprouter. Gin is designed for building REST APIs, web applications, and microservices.
Activity
- Latest release
- Feb 28, 2026
- Total releases
- 28
- Cadence
- ~2 months
- Last 12 months
- 2
Reach
- Stars
- 89.0k
Details
- First release
- Dec 03, 2016
| Version | Released | |
|---|---|---|
v1.12.0
minor
|
v1.12.0
minor
Dependencies (15)
+ 7 more |
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (14)
+ 6 more |
|
v1.10.1
patch
|
v1.10.1
patch
Dependencies (12)
+ 4 more |
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (12)
+ 4 more |
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (12)
+ 4 more |
|
v1.9.0
minor
1 CVE
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.9.0
minor
Dependencies (12)
+ 4 more |
|
v1.8.2
patch
2 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.2
patch
Dependencies (11)
+ 3 more |
|
v1.8.1
patch
2 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.1
patch
Dependencies (11)
+ 3 more |
|
v1.8.0
minor
2 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.0
minor
Dependencies (11)
+ 3 more |
|
v1.7.7
patch
2 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.7.7
patch
Dependencies (8)
|
|
v1.7.5
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (8)
|
|
v1.7.6
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (8)
|
|
v1.7.4
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (8)
|
|
v1.7.3
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (8)
|
|
v1.7.2
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (8)
|
|
v1.7.1
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (8)
|
|
v1.7.0
minor
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (8)
|
|
v1.6.3
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.6.3
patch
Dependencies (8)
|
|
v1.6.2
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (8)
|
|
v1.6.1
patch
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.6.1
patch
Dependencies (8)
|
|
v1.6.0
minor
3 CVEs
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (8)
|
|
v1.5.0
minor
5 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (8)
|
|
v1.4.0
minor
5 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-29401
GHSA-2c4m-59x9-fr2g
GO-2023-1737
May 12, 2023
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header. Fixed in
1.9.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (9)
+ 1 more |
|
v1.3.0
minor
4 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.3.0
minor
|
|
v1.1.4
patch
4 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.1.4
patch
|
|
v1.1.3
patch
4 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.1.3
patch
|
|
v1.1.2
patch
4 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.1.2
patch
|
|
v1.1.1
initial
4 CVEs
CVE-2019-25211
GHSA-869c-j7wc-8jqv
GO-2024-2955
Jun 29, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
Network
Low
None
None
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed. Fixed in
1.6.0
References
Updated Nov 03, 2025 · Source: OSV.dev
CVE-2023-26125
GHSA-3vp4-m3rf-835h
May 04, 2023
Improper input validation in github.com/gin-gonic/gin
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
Versions of the package github.com/gin-gonic/gin before version 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. Note: Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic. Fixed in
1.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-36567
GHSA-6vm3-jj99-7229
GO-2020-0001
Dec 27, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Gin is a HTTP web framework written in Go (Golang). Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. Fixed in
1.6.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-28483
GHSA-h395-qcrw-5vmq
GO-2021-0052
Jun 23, 2021
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. Fixed in
1.7.7
References Updated Mar 14, 2026 · Source: OSV.dev |
v1.1.1
initial
|