Vulnerability GO-2025-3722
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
June 03, 2025 at 05:28 PM UTC
Fabio allows HTTP clients to manipulate custom headers it adds in github.com/fabiolb/fabio
v1.0.0 - v1.6.5
v1.0.0 - v1.6.5
Summary
Fabio allows HTTP clients to manipulate custom headers it adds in github.com/fabiolb/fabio
Details
Fabio allows HTTP clients to manipulate custom headers it adds in github.com/fabiolb/fabio
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
7 hours ago
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header in github.com/fabiolb/fabio
v1.6.6 - v1.7.1 GO-2026-6566
v1.6.6 - v1.7.1 GO-2026-6566
Medium Risk
9 days ago
Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
v1.6.6 - v1.7.1 GHSA-fq95-v8xc-jm3v
v1.6.6 - v1.7.1 GHSA-fq95-v8xc-jm3v
Critical
1 year ago
Fabio allows HTTP clients to manipulate custom headers it adds
v1.0.0 - v1.6.5 GHSA-q7p4-7xjv-j3wf
v1.0.0 - v1.6.5 GHSA-q7p4-7xjv-j3wf
Impacted packages
Timeline
Published
1 year ago
June 03, 2025 at 05:28 PM UTC
Last Modified
1 year ago
June 03, 2025 at 05:58 PM UTC