{"id":"CVE-2019-11289","aliases":["GHSA-5796-p3m6-9qj4","GO-2021-0102"],"url":"https://o3.security/vulnerability/CVE-2019-11289","summary":"Cloud Foundry Routing Improper Input Validation vulnerability","details":"Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.","published":"2019-11-19T19:15:23.673Z","modified":"2026-07-08T18:17:40.798432Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"code.cloudfoundry.org/gorouter","fixedVersion":"0.0.0-20191101214924-b1b5c44e050f"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2019-11289"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T18:17:40.798432Z"}}