{"id":3494159,"name":"github.com/gorilla/csrf","ecosystem":"go","description":"Package csrf (gorilla/csrf) provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications \u0026 services.","homepage":"https://github.com/gorilla/csrf","licenses":"BSD-3-Clause","normalized_licenses":["BSD-3-Clause"],"repository_url":"https://github.com/gorilla/csrf","keywords_array":[],"namespace":"github.com/gorilla","versions_count":10,"first_release_published_at":"2015-08-05T05:46:41.000Z","latest_release_published_at":"2025-01-23T20:14:50.000Z","latest_release_number":"v1.7.3","last_synced_at":"2026-10-06T09:15:33.331Z","created_at":"2022-04-10T19:22:35.350Z","updated_at":"2026-10-06T17:50:56.251Z","registry_url":"https://pkg.go.dev/github.com/gorilla/csrf","install_command":"go get github.com/gorilla/csrf","documentation_url":"https://pkg.go.dev/github.com/gorilla/csrf#section-documentation","metadata":null,"repo_metadata":{"id":35815094,"uuid":"40097643","full_name":"gorilla/csrf","owner":"gorilla","description":"Package gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications \u0026 services 🔒","archived":false,"fork":false,"pushed_at":"2025-04-14T02:56:35.000Z","size":153,"stargazers_count":1212,"open_issues_count":38,"forks_count":178,"subscribers_count":22,"default_branch":"main","last_synced_at":"2026-10-06T14:39:31.149Z","etag":null,"topics":["csrf","csrf-protection","csrf-tokens","go","golang","gorilla","gorilla-web-toolkit","middleware","security","xsrf"],"latest_commit_sha":null,"homepage":"https://gorilla.github.io","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gorilla.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2015-08-03T00:35:16.000Z","updated_at":"2026-09-29T15:59:45.000Z","dependencies_parsed_at":"2023-01-16T06:57:38.495Z","dependency_job_id":"28b8ce00-26c4-41b5-80eb-d665f2e12d29","html_url":"https://github.com/gorilla/csrf","commit_stats":{"total_commits":87,"total_committers":29,"mean_commits":3.0,"dds":0.3793103448275862,"last_synced_commit":"a009743572494ccbc9d159005bdc58b86a44ddba"},"previous_names":[],"tags_count":16,"template":false,"template_full_name":null,"purl":"pkg:github/gorilla/csrf","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gorilla","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/sbom","scorecard":{"id":441601,"data":{"date":"2025-08-11","repo":{"name":"github.com/gorilla/csrf","commit":"9dd6af1f6d30fc79fb0d972394deebdabad6b5eb"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.9,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Code-Review","score":5,"reason":"Found 16/29 approved changesets -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/issues.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/security.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/verify.yml:10","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issues.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/issues.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/security.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/security.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/security.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/security.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/security.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/security.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/security.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/security.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/test.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/verify.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/verify.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/gorilla/csrf/verify.yml/main?enable=pin","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/gorilla/.github/SECURITY.md:1","Info: Found linked content: github.com/gorilla/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/gorilla/.github/SECURITY.md:1","Info: Found text in security policy: github.com/gorilla/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Vulnerabilities","score":9,"reason":"1 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3607 / GHSA-rq77-p4h8-4crw"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 28 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T05:42:35.887Z","repository_id":35815094,"created_at":"2025-08-19T05:42:35.887Z","updated_at":"2025-08-19T05:42:35.887Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":343170754,"owners_count":38095624,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-10-03T21:59:58.778Z","status":"online","status_checked_at":"2026-10-06T02:00:06.537Z","response_time":86,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"gorilla","name":"Gorilla web toolkit","uuid":"489566","kind":"organization","description":"Gorilla is a web toolkit for the Go programming language that provides useful, composable packages for writing HTTP-based applications.","email":"gorilla-maintainers@googlegroups.com","website":"https://gorilla.github.io","location":"The World","twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/489566?v=4","repositories_count":19,"last_synced_at":"2026-10-06T10:48:47.090Z","metadata":{"has_sponsors_listing":false,"funding":null},"html_url":"https://github.com/gorilla","funding_links":[],"total_stars":57771,"followers":1961,"following":0,"created_at":"2022-11-04T06:25:02.781Z","updated_at":"2026-10-06T10:48:47.150Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gorilla","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gorilla/repositories"},"tags":[{"name":"v1.7.3","sha":"9dd6af1f6d30fc79fb0d972394deebdabad6b5eb","kind":"commit","published_at":"2025-01-23T20:14:50.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.7.3","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.7.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.3/manifests"},{"name":"v1.7.2","sha":"a009743572494ccbc9d159005bdc58b86a44ddba","kind":"commit","published_at":"2023-11-05T02:08:39.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.7.2","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.2/manifests"},{"name":"v1.7.1","sha":"b69cbb30a1ca62a91c30fc52f16a3cb24a73a8f7","kind":"commit","published_at":"2021-07-29T15:50:12.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.7.1","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.1/manifests"},{"name":"v1.7.0","sha":"79c60d0e4fcf1fbc9653c1cb13d28e82248cf43c","kind":"commit","published_at":"2020-04-26T17:13:33.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.7.0","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.7.0/manifests"},{"name":"v1.6.2","sha":"4b50158aba1b9683db9b198ddc61436713e778f8","kind":"commit","published_at":"2019-10-08T02:23:26.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.6.2","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.2/manifests"},{"name":"v1.6.1","sha":"7b29b05df5ae7dc777b92fab3dadee1b15d15ed6","kind":"commit","published_at":"2019-08-26T00:41:49.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.6.1","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.1/manifests"},{"name":"v1.6.0","sha":"38c9e4619f0d5d8ff3fb574fc6260901f2495776","kind":"commit","published_at":"2019-06-26T01:18:22.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.6.0","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.6.0/manifests"},{"name":"v1.5.1","sha":"05b4a732b984ec326cac085631060968d4706b17","kind":"commit","published_at":"2018-05-22T06:16:36.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.5.1","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.5.1/manifests"},{"name":"v1.5","sha":"69581736821c33d85bbf378f42f6ad864dbd85de","kind":"commit","published_at":"2016-11-22T16:45:00.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.5","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.5/manifests"},{"name":"v1.4","sha":"50eb875b7d37289a5819742f0d60fa5c890fced9","kind":"commit","published_at":"2016-06-02T03:51:45.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.4","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.4/manifests"},{"name":"v1.3","sha":"fc3cfc6210838ea7c21d7c9d4f830730deda6fd0","kind":"tag","published_at":"2016-02-24T15:26:20.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.3","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.3/manifests"},{"name":"v1.2","sha":"5af6691526738a5d3e55fb49651ff9a2e03e8710","kind":"commit","published_at":"2015-11-30T01:45:03.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.2","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.2/manifests"},{"name":"v1.1","sha":"df1d6a272dddb65f6dfc805f029de2dae3311796","kind":"tag","published_at":"2015-10-19T22:37:49.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.1","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.1/manifests"},{"name":"v1.0.2","sha":"745311847bda93768d57a9dfdcfdcc3d7d01cba7","kind":"tag","published_at":"2015-08-26T04:59:30.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.0.2","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"75d51aac176500faacff469dd2fa73c279a34b53","kind":"tag","published_at":"2015-08-05T05:47:04.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.0.1","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0.1/manifests"},{"name":"v1.0","sha":"cbe8b01f8e76bab1292d173495185d3e137cf82c","kind":"tag","published_at":"2015-08-05T04:26:37.000Z","download_url":"https://codeload.github.com/gorilla/csrf/tar.gz/v1.0","html_url":"https://github.com/gorilla/csrf/releases/tag/v1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/gorilla/csrf@v1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/tags/v1.0/manifests"}]},"repo_metadata_updated_at":"2026-10-06T17:50:56.251Z","dependent_packages_count":384,"downloads":null,"downloads_period":null,"dependent_repos_count":2067,"rankings":{"downloads":null,"dependent_repos_count":0.1807226415799018,"dependent_packages_count":0.20791810204475267,"stargazers_count":2.088382245534825,"forks_count":2.2198199618842898,"docker_downloads_count":0.3375840847881748,"average":1.0068854071663889},"purl":"pkg:golang/github.com/gorilla/csrf","advisories":[{"uuid":"GSA_kwCzR0hTQS04MmZmLWhnNTktOHg3M84ABLkr","url":"https://github.com/advisories/GHSA-82ff-hg59-8x73","title":"github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks","description":"Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks.\n\nAfter the CVE-2025-24358 fix, a network attacker that places a form at http://example.com can't get it to submit to https://example.com because the Origin header is checked with sameOrigin against a synthetic URL.\n\nHowever, if a host is added to TrustedOrigins, both its HTTP and HTTPS origins will be allowed, because the schema of the synthetic URL is ignored and only the host is checked. For example, if an application is hosted on https://example.com and adds example.net to TrustedOrigins, a network attacker can serve a form at http://example.net to perform the attack.\n\nApplications should migrate to net/http.CrossOriginProtection, introduced in Go 1.25. If that is not an option, a backport is available as a module at filippo.io/csrf, and a drop-in replacement for the github.com/gorilla/csrf API is available at filippo.io/csrf/gorilla.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-08-29T20:23:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-47909","https://github.com/golang/vulndb/issues/3884","https://pkg.go.dev/vuln/GO-2025-3884","https://github.com/advisories/GHSA-82ff-hg59-8x73"],"source_kind":"github","identifiers":["GHSA-82ff-hg59-8x73","CVE-2025-47909"],"repository_url":"https://github.com/golang/vulndb","blast_radius":15.250566192485525,"created_at":"2025-08-29T21:11:13.435Z","updated_at":"2026-09-25T12:07:25.655Z","epss_percentage":0.00172,"epss_percentile":0.05755,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04MmZmLWhnNTktOHg3M84ABLkr","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04MmZmLWhnNTktOHg3M84ABLkr","packages":[{"ecosystem":"go","package_name":"github.com/gorilla/csrf","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.7.3"}],"purl":"pkg:go/github.com%2Fgorilla%2Fcsrf"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04MmZmLWhnNTktOHg3M84ABLkr/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycTc3LXA0aDgtNGNyd84ABGvu","url":"https://github.com/advisories/GHSA-rq77-p4h8-4crw","title":"gorilla/csrf CSRF vulnerability due to broken Referer validation","description":"### Summary\n\ngorilla/csrf is vulnerable to CSRF via form submission from origins that share a top level domain with the target origin.\n\n### Details\n\ngorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests only when it believes the request is being served over TLS. It determines this by inspecting the `r.URL.Scheme` value. However, this value is never populated for \"server\" requests [per the Go spec](https://pkg.go.dev/net/http#Request), and so this check does not run in practice. \n```\n\t// URL specifies either the URI being requested (for server\n\t// requests) or the URL to access (for client requests).\n\t//\n\t// For server requests, the URL is parsed from the URI\n\t// supplied on the Request-Line as stored in RequestURI.  For\n\t// most requests, fields other than Path and RawQuery will be\n\t// empty. (See [RFC 7230, Section 5.3](https://rfc-editor.org/rfc/rfc7230.html#section-5.3))\n\t//\n\t// For client requests, the URL's Host specifies the server to\n\t// connect to, while the Request's Host field optionally\n\t// specifies the Host header value to send in the HTTP\n\t// request.\n\tURL *[url](https://pkg.go.dev/net/url).[URL](https://pkg.go.dev/net/url#URL)\n```\n\n### PoC\n\n- create trusted origin `target.example.test` protected with gorilla/csrf and served over TLS hosting form on `/submit`\n- create attacker origin `attack.example.test` served over TLS\n- attacker exfiltrates token \u0026 cookie combination from `target.example.test` \n- attacker sets exfiltrated cookie with `domain=.example.test and path=/submit`\n  - as the cookie has a more specific path than `/` (the default for CSRF cookies) it will be sent first by the browser on submit to our target origin\n- submit form from `attack.example.test` with exfiltrated CSRF form token\n- observe valid form submission as `attack.example.test` Origin / Referer headers are not validated. \n\n### Impact\n\nThis vulnerability allows an attacker who has gained XSS on a subdomain or top level domain to perform authenticated form submissions against gorilla/csrf protected targets that share the same top level domain.\n\nThis bug has existed in gorilla/csrf since its initial release in 2015.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-04-14T15:26:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","references":["https://github.com/gorilla/csrf/security/advisories/GHSA-rq77-p4h8-4crw","https://github.com/gorilla/csrf/commit/9dd6af1f6d30fc79fb0d972394deebdabad6b5eb","https://nvd.nist.gov/vuln/detail/CVE-2025-24358","https://pkg.go.dev/vuln/GO-2025-3607","https://lists.debian.org/debian-lts-announce/2025/05/msg00002.html","https://github.com/advisories/GHSA-rq77-p4h8-4crw"],"source_kind":"github","identifiers":["GHSA-rq77-p4h8-4crw","CVE-2025-24358"],"repository_url":"https://github.com/gorilla/csrf","blast_radius":17.902838573787356,"created_at":"2025-04-14T16:08:46.999Z","updated_at":"2026-09-25T12:08:16.137Z","epss_percentage":0.00368,"epss_percentile":0.27872,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTc3LXA0aDgtNGNyd84ABGvu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycTc3LXA0aDgtNGNyd84ABGvu","packages":[{"ecosystem":"go","package_name":"github.com/gorilla/csrf","versions":[{"first_patched_version":"1.7.3","vulnerable_version_range":"\u003c 1.7.3"}],"purl":"pkg:go/github.com%2Fgorilla%2Fcsrf"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTc3LXA0aDgtNGNyd84ABGvu/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/gorilla/csrf","docker_dependents_count":127,"docker_downloads_count":73701561,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/gorilla/csrf","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/gorilla/csrf/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-10-01T18:13:48.021Z","issues_count":84,"pull_requests_count":66,"avg_time_to_close_issue":6257890.815384615,"avg_time_to_close_pull_request":4947770.29787234,"issues_closed_count":65,"pull_requests_closed_count":47,"pull_request_authors_count":31,"issue_authors_count":80,"avg_comments_per_issue":3.6547619047619047,"avg_comments_per_pull_request":1.0151515151515151,"merged_pull_requests_count":33,"bot_issues_count":0,"bot_pull_requests_count":0,"past_year_issues_count":2,"past_year_pull_requests_count":8,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":911.0,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":1,"past_year_pull_request_authors_count":5,"past_year_issue_authors_count":2,"past_year_avg_comments_per_issue":4.0,"past_year_avg_comments_per_pull_request":0.125,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":0,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/gorilla%2Fcsrf/issues","maintainers":[{"login":"elithrar","count":18,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/elithrar"},{"login":"apoorvajagtap","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/apoorvajagtap"}],"active_maintainers":[]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fgorilla%2Fcsrf/codemeta","maintainers":[]}