Description
parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.
Published: 2024-06-28
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4285-1 golang-github-gin-contrib-cors security
EUVD EUVD EUVD-2024-1974 parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention is that only http://localhost/* should be allowed.
Github GHSA Github GHSA GHSA-869c-j7wc-8jqv Gin mishandles a wildcard at the end of an origin string
History

Mon, 03 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
References

Fri, 25 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Gin-contrib
Gin-contrib cors
CPEs cpe:2.3:a:gin-contrib:cors:*:*:*:*:*:*:*:*
Vendors & Products Gin-contrib
Gin-contrib cors
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Sep 2024 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat rhmt
CPEs cpe:/a:redhat:rhmt:1.8::el8
Vendors & Products Redhat
Redhat rhmt

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-03T18:07:54.695Z

Reserved: 2024-06-28T00:00:00.000Z

Link: CVE-2019-25211

cve-icon Vulnrichment

Updated: 2025-11-03T18:07:54.695Z

cve-icon NVD

Status : Deferred

Published: 2024-06-29T00:15:02.107

Modified: 2026-04-15T00:35:42.020

Link: CVE-2019-25211

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-02T00:00:00Z

Links: CVE-2019-25211 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses