CVE-2025-22870: Go Standard Library Net/http
Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
Affected products
- Go Standard Library Net/http: before 1.23.7 (fixed in 1.23.7); from 1.24.0-0, before 1.24.1 (fixed in 1.24.1)
- Golang.org/x/net Golang.org/x/net/http/httpproxy: before 0.36.0 (fixed in 0.36.0)
- Golang.org/x/net Golang.org/x/net/proxy: before 0.36.0 (fixed in 0.36.0)
Published 2025-03-12. Last modified 2026-06-17.