Skip to content

[GHSA-86p5-cmgc-c94w] In Eclipse BaSyx Go Components versions up to and... - #9907

Open
portyu9 wants to merge 1 commit into
portyu9/advisory-improvement-9907from
portyu9-GHSA-86p5-cmgc-c94w
Open

portyu9 wants to merge 1 commit into
portyu9/advisory-improvement-9907from
portyu9-GHSA-86p5-cmgc-c94w

Conversation

@portyu9

@portyu9 portyu9 commented Sep 30, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • Source code location
  • Summary

Comments
Add the missing Go module mapping, affected/patched version information, summary, CVSS 4.0 vector, and source code location for CVE-2026-15704 / GHSA-86p5-cmgc-c94w.

The affected Go module is github.com/eclipse-basyx/basyx-go-components, as declared by the root go.mod at both the vulnerable v1.0.0 tag and the fixed v1.0.1 tag.

In v1.0.0, internal/common/router_error_handlers.go configures API routers with Chi's middleware.StripSlashes. In ABAC-enabled deployments, authorization evaluates the original request path while the router can subsequently strip the trailing slash and dispatch the corresponding protected non-slash route. An unauthorized request such as /shells/ can therefore miss the intended ABAC route decision and still reach the /shells handler.

The upstream fix eclipse-basyx/basyx-go-components#442 removes StripSlashes from ConfigureAPIRouter. Its regression tests explicitly change trailing-slash requests from successful or method-matched routing to HTTP 404 and verify that the protected collection handler is not called. Additional integration cases cover trailing-slash requests across repository, registry, discovery, upload, and related service routes.

Affected package: github.com/eclipse-basyx/basyx-go-components
Affected versions: <= 1.0.0
Patched version: 1.0.1

Vulnerable source:
https://github.com/eclipse-basyx/basyx-go-components/blob/v1.0.0/internal/common/router_error_handlers.go#L40-L45

Fixed release:
https://github.com/eclipse-basyx/basyx-go-components/releases/tag/v1.0.1

@github-actions
github-actions Bot changed the base branch from main to portyu9/advisory-improvement-9907 September 30, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant