VDB
Sign up
—

GO-2023-1526

Server-side request forgery in github.com/hakobe/paranoidhttp

Quick fix

GO-2023-1526 — github.com/hakobe/paranoidhttp: upgrade to the fixed version with the command below.

go get github.com/hakobe/paranoidhttp@v0.3.0

Details

Paranoidhttp before is vulnerable to SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hakobe/paranoidhttp
Introduced in: 0Fixed in: 0.3.0
Fixgo get github.com/hakobe/paranoidhttp@v0.3.0

References