pkg.go.dev package intelligence

github.com/gin-gonic/gin — deep security report

ShadowCanopy's full breakdown of github.com/gin-gonic/gin on pkg.go.dev: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Caution — flagged for review
Our scan found suspicious behavior worth reviewing before you install this package.
Scanned 7/28/2026
Flaggedgithub.com/gin-gonic/gin@0.20.30View on registry ↗latest: 0.20.30

Not found in the go registry — this version appears unpublished, never existed, or is a private/internal package. It isn't installable from the public registry; upload it for review if it's a custom package.

Protect your projects free

Security findings (1)

Static analysis rule matches, with the exact code that triggered them.

highNot published in the public registryREG-404package.json

"github.com/gin-gonic/gin@0.20.30" could not be fetched from the go registry. It may be unpublished, have never existed, or be a private/internal package the cloud can't see. This is re-checked on every scan (never cached) because a currently-missing name can be published at any time (dependency confusion). If it's a legitimate custom package, upload it for review so ShadowCanopy can inspect its code and remember it.

Known vulnerabilities (6)

Published CVEs / advisories affecting this version.

GHSA-869c-j7wc-8jqvCRITICAL

Gin mishandles a wildcard at the end of an origin string

GHSA-6vm3-jj99-7229HIGH

Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines

GHSA-h395-qcrw-5vmqHIGH

Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin

GHSA-3vp4-m3rf-835hMODERATE

Improper input validation in github.com/gin-gonic/gin

GO-2020-0001UNKNOWN

Arbitrary log line injection in github.com/gin-gonic/gin

GO-2021-0052UNKNOWN

Inconsistent interpretation of HTTP Requests in github.com/gin-gonic/gin

How ShadowCanopy checks pkg.go.dev packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/go/github.com/gin-gonic/gin