CVE-2025-71405

Source
https://cve.org/CVERecord?id=CVE-2025-71405
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71405.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-71405
Aliases
Published
2026-08-14T11:35:23.411Z
Modified
2026-08-16T03:48:26.144202672Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
go-chi chi before v5.2.2 Open Redirect via RedirectSlashes
Details

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71405.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/go-chi/chi

Affected ranges

Type
GIT
Repo
https://github.com/go-chi/chi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.2.2"
        },
        {
            "fixed": "v5.2.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.9.0
v1.*
v1.0.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v2.*
v2.0.0
v2.1.0
v3.*
v3.0.0
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.2.0
v3.2.1
v3.3.0
v3.3.1
v3.3.2
v3.3.3
v3.3.4
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.1.0
v4.1.1
v4.1.2
v5.*
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71405.json"