CVE-2020-12666 is a medium-severity (CVSS 6.1) Open Redirect vulnerability in gopkg.in/macaron.v1. 1 public exploit reference exists, so weaponization risk is real. A fix is available for gopkg.in/macaron.v1 — see the affected versions and patch details below.
gopkg.in/macaron.v1 Open Redirect vulnerability
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2020-12666 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
gopkg.in/macaron.v1Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.
Description
macaron before 1.3.7 has an open redirect in the static handler. Due to improper request santization, a specifically crafted URL can cause the static file handler to redirect to an attacker chosen URL, allowing for open redirect attacks.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐹Go | gopkg.in/macaron.v1 | all versions | 1.3.7go get gopkg.in/macaron.v1@v1.3.7 |
Affected Products
fedorafedoraprojectmacarongo-macaronResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for gopkg.in/macaron.v1, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update gopkg.in/macaron.v1 to 1.3.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2020-12666 is resolved across your whole dependency graph.
Workarounds
Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This issue has a low impact on both OpenShift Container Platform and OpenShift Service Mesh grafana containers. As neither components make use of the Static handler the impact is Low. A future version of Grafana may use the Macaron Static handler so we may fix this in a future release. Red Hat Ceph Storage (RHCS)…
| Product | Fixed in | Advisory |
|---|---|---|
| Openshift Service Mesh 1.1 | kiali-0:v1.12.10.redhat2-1.el7 | RHSA-2020:3369 |
Frequently Asked Questions
Is CVE-2020-12666 in your dependencies?
Find it across Go, including transitive dependencies.