PT-2026-71978 · Chi · Chi

·

CVE-2025-71405

·

Published

2025-06-20

·

Updated

2026-08-14

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions chi versions prior to v5.2.2
Description The RedirectSlashes() middleware function uses the Host header to construct redirect URLs. An attacker can manipulate this header to redirect users to arbitrary external hosts, which can be used to facilitate phishing attacks and the theft of credentials.
Recommendations Update to version v5.2.2 or later. As a temporary workaround, consider disabling the RedirectSlashes() middleware function until the update is applied.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71405
GHSA-VRW8-FXC6-2R93
GO-2025-3770

Affected Products

Chi