Skip to main content

Vendor archive

gin-gonic CVEs

Beta · best-effort

4 CVEs tagged to vendor gin-gonic0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-29401

Published Jun 8, 2023

The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26125

Published May 4, 2023

Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forw…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36567

Published Dec 27, 2022

Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28483

Published Jan 20, 2021

This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1