CVE-2023-26125 describes an Improper Input Validation vulnerability in versions of the github.com/gin-gonic/gin package prior to 1.9.0. An attacker can exploit this by crafting a malicious X-Forwarded-Prefix header, potentially leading to cache poisoning. While not a significant threat in isolation, it can serve as an input vector for more impactful vulnerabilities, with successful exploitation dependent on server configuration and application logic. The vulnerability has a CVSS v3.1 score of 7.3 (HIGH), indicating a network-based attack with low complexity and no required privileges or user interaction, potentially impacting confidentiality, integrity, and availability. Its EPSS score is low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, aligning with typical trends for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.0CPE matchmatch criteria | cpe:2.3:a:gin-gonic:gin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - October 2024
Oct 14, 2024Improper input validation in github.com/gin-gonic/gin
May 4, 2023golang-github-gin-gonic-gin: Improper Input Validation
May 4, 2023