Gin Gonic is a lightweight HTTP web framework for Go that, despite a narrow product scope, serves as a dependency across a substantial range of Go-based applications and microservices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gin Gonic over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28483HIGH This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. | Jan 20, 2021 | 7.1 | 23 | NO | NO |
CVE-2023-26125HIGH Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a specially crafted request via the X-Forwa | May 4, 2023 | 7.3 | 22 | NO | NO |
CVE-2020-36567HIGH Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. | Dec 27, 2022 | 7.5 | 22 | NO | NO |
CVE-2023-29401MEDIUM The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an | Jun 8, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gin Gonic.
Media articles that mention a CVE ID that affects a product developed by Gin Gonic — matched by CVE ID, not by vendor name.