HIGH7.5
GHSA-5x84-q523-vvwr
nosurf vulnerable to improper input validation
Quick fix
GHSA-5x84-q523-vvwr — github.com/justinas/nosurf: upgrade to the fixed version with the command below.
go get github.com/justinas/nosurf@v1.1.1Details
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/justinas/nosurf
Introduced in:
0Fixed in: 1.1.1Fix
go get github.com/justinas/nosurf@v1.1.1