CVE-2025-47912

Published: October 9, 2025Last modified: December 23, 2025

Description

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.24.8-r0)
25 LTSgoFixed (1.24.8-r0)
StreamgoFixed (1.25.2-r0)
Hardened Containers23 LTSgoFixed (1.24.8-r0)
25 LTSgoFixed (1.24.8-r0)
StreamgoFixed (1.25.2-r0)

References

ON THIS PAGE