CVE-2024-24790: Golang Go
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Affected products
- Golang Go: before 1.21.11 (fixed in 1.21.11); from 1.22.0, before 1.22.4 (fixed in 1.22.4)
Published 2024-06-05. Last modified 2026-06-17.