CVE-2025-71405

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-14 12:16

Updated : 2026-08-14 19:17


NVD link : CVE-2025-71405

Mitre link : CVE-2025-71405

CVE.ORG link : CVE-2025-71405


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')