When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.
{ "binaries": [ { "binary_name": "golang-1.8", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-go", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-go-shared-dev", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-src", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "libgolang-1.8-std1", "binary_version": "1.8.3-2ubuntu1.18.04.1" } ] }