{"id":"GHSA-h395-qcrw-5vmq","summary":"Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin","details":"When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7. ","aliases":["CVE-2020-28483","GO-2021-0052","SNYK-GOLANG-GITHUBCOMGINGONICGIN-1041736"],"modified":"2026-05-07T04:56:47.934609746Z","published":"2021-06-23T17:53:21Z","database_specific":{"github_reviewed_at":"2021-05-12T21:46:50Z","nvd_published_at":"2021-01-20T18:15:00Z","cwe_ids":["CWE-113","CWE-444"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28483"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/issues/2232"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/issues/2473"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/issues/2862"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2474"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2474#23issuecomment-729696437"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2632"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2675"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2844"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/pull/2844/files#diff-e6ce689a25eaef174c2dd51fe869fabbe04a6c6afbd416b23eda138c82e761baR1432"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/commit/03e5e05ae089bc989f1ca41841f05504d29e3fd9"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/commit/5929d521715610c9dd14898ebbe1d188d5de8937"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/commit/bfc8ca285eb46dad60e037d57c545cd260636711"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGINGONICGIN-1041736"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2021-0052"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/releases/tag/v1.7.7"},{"type":"WEB","url":"https://github.com/gin-gonic/gin/releases/tag/v1.7.0"},{"type":"PACKAGE","url":"https://github.com/gin-gonic/gin"}],"affected":[{"package":{"name":"github.com/gin-gonic/gin","ecosystem":"Go","purl":"pkg:golang/github.com/gin-gonic/gin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-h395-qcrw-5vmq/GHSA-h395-qcrw-5vmq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}