Junglewise Threat Intelligence

CVE-2025-22870: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

CVE-2025-22870 · Severity: medium · CVSS 4.4 · Published 2025-03-12

Technologies: stdlib (Go), golang.org/x/net (Go). Vendors: Go.

Executive brief

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

Affected products

  • Go stdlib
  • Go golang.org/x/net

References

Related threats