{"id":"CVE-2019-25211","aliases":["GHSA-869c-j7wc-8jqv","GO-2024-2955"],"url":"https://o3.security/vulnerability/CVE-2019-25211","summary":"Gin mishandles a wildcard at the end of an origin string","details":"parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.","published":"2024-06-29T00:15:02.107Z","modified":"2026-07-08T16:27:57.292478Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00431,"percentile":0.36716,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gin-gonic/gin","fixedVersion":"1.6.0"},{"ecosystem":"Go","name":"github.com/gin-contrib/cors","fixedVersion":"1.6.0"}],"fix":{"url":"https://github.com/gin-contrib/cors/commit/27b723a473efd80d5a498fa9f5933c80204c850d","label":"gin-contrib/cors@27b723a"},"references":[{"type":"WEB","url":"https://github.com/gin-contrib/cors/compare/v1.5.0...v1.6.0"},{"type":"WEB","url":"https://github.com/gin-contrib/cors/releases/tag/v1.6.0"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/08/msg00024.html"},{"type":"FIX","url":"https://github.com/gin-contrib/cors/commit/27b723a473efd80d5a498fa9f5933c80204c850d"},{"type":"FIX","url":"https://github.com/gin-contrib/cors/pull/106"},{"type":"FIX","url":"https://github.com/gin-contrib/cors/pull/57"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:27:57.292478Z"}}