github.com/rs/cors
Activity
- Latest release
- 2y ago
- Total releases
- 14
- Cadence
- ~5 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Jan 23, 2018
| Version | Released | |
|---|---|---|
v1.11.1
patch
|
v1.11.1
patch
|
|
v1.11.0
minor
|
v1.11.0
minor
|
|
v1.10.1
patch
1 CVE
CVE-2025-47908
GHSA-mh55-gqvf-xfwm
GO-2024-2883
Jul 05, 2024
Denial of service via malicious preflight requests in github.com/rs/cors
Medium
Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service. Fixed in
1.11.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v1.10.1
patch
|
|
v1.10.0
minor
1 CVE
CVE-2025-47908
GHSA-mh55-gqvf-xfwm
GO-2024-2883
Jul 05, 2024
Denial of service via malicious preflight requests in github.com/rs/cors
Medium
Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service. Fixed in
1.11.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v1.10.0
minor
|
|
v1.9.0
minor
1 CVE
CVE-2025-47908
GHSA-mh55-gqvf-xfwm
GO-2024-2883
Jul 05, 2024
Denial of service via malicious preflight requests in github.com/rs/cors
Medium
Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service. Fixed in
1.11.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v1.9.0
minor
|
|
v1.8.3
patch
|
v1.8.3
patch
|
|
v1.8.2
patch
|
v1.8.2
patch
|
|
v1.8.1
patch
|
v1.8.1
patch
|
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (1)
|
|
v1.7.0
minor
|
v1.7.0
minor
|
|
v1.6.0
minor
|
v1.6.0
minor
|
|
v1.5.0
minor
|
v1.5.0
minor
|
|
v1.4.0
minor
1 CVE
CVE-2018-20744
GO-2023-1792
GHSA-927h-x4qj-r242
Jun 08, 2023
Insecure wildcard CORS policy in github.com/rs/cors The CORS handler actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
1.5.0
Updated May 20, 2024 · Source: OSV.dev |
v1.4.0
minor
|
|
v1.3.0
initial
1 CVE
CVE-2018-20744
GO-2023-1792
GHSA-927h-x4qj-r242
Jun 08, 2023
Insecure wildcard CORS policy in github.com/rs/cors The CORS handler actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems. Fixed in
1.5.0
Updated May 20, 2024 · Source: OSV.dev |
v1.3.0
initial
|