Published: 29 June 2024

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g.,* is allowed when the intention is that only* should be allowed, and* is allowed when the intention is that only http://localhost/* should be allowed.




Package Release Status
Launchpad, Ubuntu, Debian
focal Needs triage

jammy Needs triage

mantic Ignored
(end of life, was needs-triage)
noble Needs triage

upstream Needs triage