#CSRF
In which I survey CSRF countermeasures and existing Go libraries and propose we add CrossOriginForgeryHandler to net/http to solve this once and for all.

Turns out there is no need for tokens or keys in 2025! Browsers just send a This-Is-CSRF header now. (Sort of.)

https://github.com/golang/go/iss
May 7, 2025 at 4:36 PM
I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions.

I'm not gonna recite them again here, but today a new condition came up:

No Content-Type header -> no CSRF restrictions
Same-site: None
POST
= CSRF

The research:
November 27, 2024 at 4:55 PM
Hi. For anyone seeing this, this is fake (or likely misiattributed). The survey in question didn't ask for authentication. On top of that, clicking a link can't steal your auth token because that would be a MAJOR CSRF exploit. Also, here's the survey site's SSL cert info.
January 11, 2026 at 5:09 AM
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
www.bleepingcomputer.com
September 25, 2026 at 6:13 PM
CSRF attack and prevention #cybersecurity
December 1, 2024 at 6:28 AM
Got a CSRF attack being blocked by Content-Type validation? You might be able to bypass it with this quality technique.
My latest blog post is live! nastystereo.com/security/cro...

Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
November 27, 2024 at 1:28 PM
I'm looking into github.com/gorilla/csrf to figure out if we could bring CSRF protection to the standard library.

I am 90% sure the secret key is useless: it signs a random token with no metadata, and the attacker can just get and reuse a valid signed token.

Am I missing something?
April 17, 2025 at 10:05 AM
I implemented the proposed CSRF handler, if anyone wants to test it, or wants to migrate before it makes its way into the standard library.

There are are no tokens or cookies, so migrating should be easy, but note that it applies strict same-origin checks.

Feedback welcome!

filippo.io/csrf
May 16, 2025 at 9:16 PM
HAPPY BLACK HISTORY MONTH BLACK AMERICANS!!!

❤️💚🖤

I posted this months first cybersecurity lesson on:

- GET & POST Requests
- Session Termination
- CSRF
- XSS

✊🏽✊🏾✊🏿

#Cybersecurity
#HACKTHEPLANET
www.tiktok.com/t/ZT2jtT2AM/
Happy Black History Month #HillmanTokHackers!!! Let's start the month off learning all things: - Session Termination - CSRF - XSS Comment something you learned from tonight's video and share it with...
TikTok video by 𝐃𝐈𝐆𝐈𝐓𝐀𝐋 𝐄𝐌𝐏𝐑𝐄𝐒𝐒
www.tiktok.com
February 1, 2025 at 6:34 AM
Does widespread browser implementation of the Sec-Fetch-Site HTTP header mean we can protect against CSRF attacks without needing those hidden form tokens? It looks like the answer may be a cautious "yes"! simonwillison.net/2025/Oct/15/...
A modern approach to preventing CSRF in Go
Alex Edwards writes about the new http.CrossOriginProtection middleware that was added to the Go standard library in version 1.25 in August and asks: Have we finally reached the point where …
simonwillison.net
October 15, 2025 at 5:07 AM
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.
www.bleepingcomputer.com
September 21, 2026 at 6:23 PM
September 26, 2026 at 10:21 AM
s'curity
November 3, 2024 at 7:32 PM
Logout CSRF is evergreen
December 21, 2023 at 7:22 AM
THANK YOU 🙏🏻 Sam Altman for solving the HUGE problem of clicking a link in my browser without having my memories injected to be later exploited via execution 👑 what a gift genAI is
October 27, 2025 at 6:38 PM
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News
https://ift.tt/dByxFNX

https://ift.tt/v7njsAU

https://tech-happenings.lovable.app/
September 26, 2026 at 11:45 AM
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News
https://ift.tt/dByxFNX

https://ift.tt/0fytDz9

https://tech-happenings.lovable.app/
September 26, 2026 at 11:30 AM
GraphQL CSRF via the HEAD method #bugbounty #bugbountytips #bugbountyhunter
June 30, 2025 at 10:51 AM
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News
https://ift.tt/dByxFNX

https://ift.tt/phaWdBq

https://tech-happenings.lovable.app/
September 26, 2026 at 12:00 PM
CSRF attacks are essentially dead in Go 1.25.

Really happy to see this, I can finally remove nosurf from Faktory.

https://www.alexedwards.net/blog/preventing-csrf-in-go
A modern approach to preventing CSRF in Go
Comments
www.alexedwards.net
October 14, 2025 at 11:03 PM
Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover

Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack...

https://thecybersecguru.com/news/elementor-cve-2026-62062-csrf-vulnerability/
September 26, 2026 at 5:58 PM
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html

#CyberSecurity #InfoSec
September 26, 2026 at 1:00 PM