CVE-2016-15005: Golf Project Golf
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.
Affected products
- Golf Project Golf: before 0.3.0 (fixed in 0.3.0)
Published 2022-12-27. Last modified 2026-06-17.