{"id":"GO-2024-2812","summary":"Some CORS middleware allow untrusted origins in github.com/jub0bs/fcors","details":"Some CORS middleware (more specifically those created by specifying two or more origin patterns whose hosts share a proper suffix) incorrectly allow some untrusted origins, thereby opening the door to cross-origin attacks from the untrusted origins in question.\n\nFor example, specifying origin patterns \"https://foo.com\" and \"https://bar.com\" (in that order) would yield a middleware that would incorrectly allow untrusted origin \"https://barfoo.com\".","aliases":["GHSA-v84h-653v-4pq9"],"modified":"2026-02-04T04:32:51.776553Z","published":"2024-05-21T15:08:01Z","related":["GHSA-vhxv-fg4m-p2w8"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2812"},"references":[{"type":"ADVISORY","url":"https://github.com/jub0bs/fcors/security/advisories/GHSA-v84h-653v-4pq9"},{"type":"FIX","url":"https://github.com/jub0bs/fcors/commit/b5dcb889a49def37d7d9c25deb7135f4eb45625e"}],"affected":[{"package":{"name":"github.com/jub0bs/fcors","ecosystem":"Go","purl":"pkg:golang/github.com/jub0bs/fcors"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.9.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/jub0bs/fcors/internal/radix","symbols":["Tree.Contains","Tree.Insert","lastByteIn","lengthOfCommonSuffix","node.add","splitRight"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2812.json"}}],"schema_version":"1.7.3"}