CVE-2020-28483: Gin-Gonic Gin
High severity, CVSS 7.1. EPSS: 1.3% chance of exploitation in the next 30 days.
This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.
Affected products
- Gin-Gonic Gin: before 1.7.0 (fixed in 1.7.0)
Published 2021-01-20. Last modified 2026-06-17.