What is CVE-2025-71405?
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware via the Host header. Attackers can redirect users to arbitrary hosts for phishing. Update chi to v5.2.2 or later to mitigate.
Azərbaycanca: chi-nin v5.2.2-dən əvvəlki versiyalarında RedirectSlashes middleware funksiyasında Host başlığına əsaslanan açıq yönləndirmə (open redirect) zəifliyi. Təcavüzkar Host başlığını manipulyasiya edərək istifadəçiləri fişinq saytlarına yönləndirə bilər. chi-ni v5.2.2 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
FAQ2
In which function of the chi library is the CVE-2025-71405 vulnerability found?
The vulnerability is found in the RedirectSlashes middleware function of chi.
What version should be updated to in order to mitigate this vulnerability?
It is recommended to update the chi library to v5.2.2 or a later version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.