—
GO-2025-3683
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf
Quick fix
GO-2025-3683 — github.com/justinas/nosurf: upgrade to the fixed version with the command below.
go get github.com/justinas/nosurf@v1.2.0Details
Vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/justinas/nosurf
Introduced in:
0Fixed in: 1.2.0Fix
go get github.com/justinas/nosurf@v1.2.0References
- https://github.com/justinas/nosurf/security/advisories/GHSA-w9hf-35q4-vcjw[ADVISORY]
- https://github.com/justinas/nosurf/commit/ec9bb776d8e5ba9e906b6eb70428f4e7b009feee[FIX]
- https://github.com/advisories/GHSA-rq77-p4h8-4crw[WEB]
- https://github.com/justinas/nosurf-cve-2025-46721[WEB]
- https://github.com/justinas/nosurf/releases/tag/v1.2.0[WEB]