High severityNVD Advisory· Published Dec 27, 2022· Updated Apr 11, 2025
Improper input validation in github.com/justinas/nosurf
CVE-2020-36564
Description
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/justinas/nosurfGo | < 1.1.1 | 1.1.1 |
Affected products
2- github.com/justinas/nosurf/github.com/justinas/nosurfv5Range: 0
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5News mentions
0No linked articles in our index yet.