VendorsGin-gonicginany version
Vulnerabilities

Gin-gonic Gin any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-36567
Arbitrary log line injection in github.com/gin-gonic/gin
Published 2022-12-27 · Modified
7.5EPSS 0.014
CVE-2023-26125
Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwarded-Prefix header, potentially leading to cache poisoning. **Note:** Although this issue does not pose a significant threat on its own it can serve as an input vector for other more impactful vulnerabilities. However, successful exploitation may depend on the server configuration and whether the header is used in the application logic.
Published 2023-05-04 · Modified
7.3EPSS 0.009
CVE-2020-28483
HTTP Response Splitting
Published 2021-01-20 · Modified
7.1EPSS 0.013
CVE-2023-29401
Improper handling of filenames in Content-Disposition HTTP header in github.com/gin-gonic/gin
Published 2023-06-08 · Modified
4.3EPSS 0.005