Headline
GHSA-5x84-q523-vvwr: nosurf vulnerable to improper input validation
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
nosurf vulnerable to improper input validation
Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022
Related news
CVE-2020-36564: GO-2020-0049 - Go Packages
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.