CVE-2016-15005: Golf Project Golf

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.

Affected products

Published 2022-12-27. Last modified 2026-06-17.