CVE-2025-47909: Improper validation of TrustedOrigins allows CSRF attacks in github.com/gorilla/csrf
Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks.
After the CVE-2025-24358 fix, a network attacker that places a form at http://example.com can't get it to submit to https://example.com because the Origin header is checked with sameOrigin against a synthetic URL.
However, if a host is added to TrustedOrigins, both its HTTP and HTTPS origins will be allowed, because the schema of the synthetic URL is ignored and only the host is checked. For example, if an application is hosted on https://example.com and adds example.net to TrustedOrigins, a network attacker can serve a form at http://example.net to perform the attack.
Applications should migrate to net/http.CrossOriginProtection, introduced in Go 1.25. If that is not an option, a backport is available as a module at filippo.io/csrf, and a drop-in replacement for the github.com/gorilla/csrf API is available at filippo.io/csrf/gorilla.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47909?
CVE-2025-47909 is considered a medium severity vulnerability due to its potential for CSRF attacks.
How do I fix CVE-2025-47909?
To fix CVE-2025-47909, ensure that your application does not use trusted origins that unnecessarily allow requests from corresponding HTTP origins.
What type of attack does CVE-2025-47909 allow?
CVE-2025-47909 allows network attackers to perform Cross-Site Request Forgery (CSRF) attacks.
Which software is affected by CVE-2025-47909?
CVE-2025-47909 affects applications built with Go version 1.25 and may also impact libraries like Filippo csrf and Gorilla csrf.
What is the main risk associated with CVE-2025-47909?
The main risk associated with CVE-2025-47909 is that it can allow an attacker to trick a user’s browser into sending unauthorized requests to a target server.