security advisorydebiangolang
An issue has been found in golang-github-gin-contrib-cors, a Gin middleware/handler to enable CORS support. The issue is related to improper wildcard handling and an attacker might be able to circumvent . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4285-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz August 28, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : golang-github-gin-contrib-cors Version : 1.3.1-1+deb11u1 CVE ID : CVE-2019-25211 An issue has been found in golang-github-gin-contrib-cors, a Gin middleware/handler to enable CORS support. The issue is related to improper wildcard handling and an attacker might be able to circumvent restrictions. For Debian 11 bullseye, this problem has been fixed in version 1.3.1-1+deb11u1. We recommend that you upgrade your golang-github-gin-contrib-cors packages. For the detailed security status of golang-github-gin-contrib-cors please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/golang-github-gin-contrib-cors Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Mitigating incorrect wildcard management in golang-github-gin-contrib-cors on Debian LTS. Urgent security patch advised.. CORS support, golang middleware, Debian security update. . LinuxSecurity.com Team
Aug 28, 2025
Debian LTS