nosurf vulnerable to CSRF due to non-functional same-origin request checks in github.com/justinas/nosurf
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-3683" }
{ "imports": [ { "path": "github.com/justinas/nosurf", "symbols": [ "CSRFHandler.ServeHTTP", "New", "NewPure" ] } ] }