github.com/justinas/nosurf
Activity
- Latest release
- 1y ago
- Total releases
- 4
- Cadence
- ~10 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Nov 05, 2019
| Version | Released | |
|---|---|---|
v1.2.0
minor
|
v1.2.0
minor
|
|
v1.1.1
patch
1 CVE
CVE-2025-46721
GO-2025-3683
GHSA-w9hf-35q4-vcjw
May 15, 2025
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Fixed in
1.2.0
References
Updated Jun 12, 2025 · Source: OSV.dev |
v1.1.1
patch
|
|
v1.1.0
minor
2 CVEs
CVE-2025-46721
GO-2025-3683
GHSA-w9hf-35q4-vcjw
May 15, 2025
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Fixed in
1.2.0
References
Updated Jun 12, 2025 · Source: OSV.dev
CVE-2020-36564
GHSA-5x84-q523-vvwr
GO-2020-0049
Dec 28, 2022
nosurf vulnerable to improper input validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid. Fixed in
1.1.1
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.0.0
initial
2 CVEs
CVE-2025-46721
GO-2025-3683
GHSA-w9hf-35q4-vcjw
May 15, 2025
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf Fixed in
1.2.0
References
Updated Jun 12, 2025 · Source: OSV.dev
CVE-2020-36564
GHSA-5x84-q523-vvwr
GO-2020-0049
Dec 28, 2022
nosurf vulnerable to improper input validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid. Fixed in
1.1.1
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.0
initial
|