UBUNTU-CVE-2025-71405

Source
https://ubuntu.com/security/CVE-2025-71405
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-71405.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-71405
Upstream
Published
2026-08-14T12:16:00Z
Modified
2026-08-19T11:01:13Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.

References

Affected packages

Ubuntu:22.04:LTS / golang-github-go-chi-chi

Package

Name
golang-github-go-chi-chi
Purl
pkg:deb/ubuntu/golang-github-go-chi-chi?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.5.1-2
5.*
5.0.7-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-go-chi-chi-dev",
            "binary_version": "5.0.7-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-71405.json"

Ubuntu:24.04:LTS / golang-github-go-chi-chi

Package

Name
golang-github-go-chi-chi
Purl
pkg:deb/ubuntu/golang-github-go-chi-chi?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.7-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-go-chi-chi-dev",
            "binary_version": "5.0.7-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-71405.json"

Ubuntu:26.04:LTS / golang-github-go-chi-chi

Package

Name
golang-github-go-chi-chi
Purl
pkg:deb/ubuntu/golang-github-go-chi-chi?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.2.0-1
5.2.3-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-go-chi-chi-dev",
            "binary_version": "5.2.3-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-71405.json"