Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23882 | Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service. |
Github GHSA |
GHSA-mh55-gqvf-xfwm | Denial of service via malicious preflight requests in github.com/rs/cors |
Tue, 12 Aug 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang cors |
|
| Vendors & Products |
Golang
Golang cors |
Thu, 07 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 07 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 06 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue load on the middleware/server as an attempt to cause a denial of service. | |
| Title | Denial of service via malicious preflight requests in github.com/rs/cors | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-08-07T13:47:15.232Z
Reserved: 2025-05-13T23:31:29.597Z
Link: CVE-2025-47908
Updated: 2025-08-07T13:46:45.866Z
Status : Deferred
Published: 2025-08-06T21:15:29.313
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-47908
OpenCVE Enrichment
Updated: 2025-08-12T07:49:26Z
EUVD
Github GHSA