Junglewise Threat Intelligence

CVE-2025-69725: go-chi chi open redirect in RedirectSlashes middleware

CVE-2025-69725 · Severity: medium · CVSS 4.7 · Published 2026-02-19

Technologies: Go-Chi Chi, github.com/go-chi/chi/v5 (Go). Vendors: Go, Go-Chi.

Executive brief

A security flaw exists in the go-chi library, a popular tool used by developers to build web applications in the Go programming language. The issue occurs in a component designed to clean up web addresses (URLs) by removing extra slashes. An attacker can use this flaw to create a deceptive link that appears to belong to a trusted website but instead redirects the user to a malicious site, potentially leading to phishing attacks or credential theft.

Technical details

An open redirect vulnerability exists in the RedirectSlashes function within middleware/strip.go of the go-chi/chi library. The function fails to validate or trim backslash (\) characters while processing path slashes, and since version 5.2.2, it does not include the Host header in redirect responses. An attacker can craft a URL starting with a backslash (e.g., '/\evil.com'), which many modern browsers (excluding Safari) interpret as a protocol-relative URL (//evil.com), resulting in a redirect to the attacker-controlled domain. This requires no authentication and is triggered when a victim clicks a malicious link. The issue is patched in version 5.2.4.

Affected products

  • go-chi chi >=5.2.2, <5.2.4

Timeline

  • 2026-01-14: advisory: GitHub Security Advisory published by maintainers
  • 2026-02-19: disclosed: CVE published to NVD
  • 2026-01-14: patched: Fix released in version 5.2.4

References

Related threats