chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go-chi
Go-chi chi |
|
| Vendors & Products |
Go-chi
Go-chi chi |
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft. | |
| Title | go-chi chi before v5.2.2 Open Redirect via RedirectSlashes | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T18:57:43.537Z
Reserved: 2026-07-18T12:38:41.077Z
Link: CVE-2025-71405
No data.
Status : Received
Published: 2026-08-14T12:16:43.297
Modified: 2026-08-14T19:17:13.263
Link: CVE-2025-71405
No data.
OpenCVE Enrichment
Updated: 2026-08-14T13:00:10Z
Weaknesses