CVE-2025-71405

NameCVE-2025-71405
Descriptionchi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-github-go-chi-chi (PTS)bookworm5.0.7-1vulnerable
trixie5.2.0-1vulnerable
forky, sid5.3.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-go-chi-chisource(unstable)5.2.3-1

Notes

[trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
[bookworm] - golang-github-go-chi-chi <ignored> (Minor issue; out of LTS support)
[bullseye] - golang-github-go-chi-chi <ignored> (Minor issue; out of LTS support)
https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93

Search for package or bug name: Reporting problems