| Name | CVE-2025-71405 |
| Description | chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
[trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
[bookworm] - golang-github-go-chi-chi <ignored> (Minor issue; out of LTS support)
[bullseye] - golang-github-go-chi-chi <ignored> (Minor issue; out of LTS support)
https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93