CVE-2025-22870 Information

Description

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example when the NO_PROXY environment variable is set to .example.com\ a request to [::1%25.example.com]:80` will incorrectly match and not be proxied.

Reference

http://www.openwall.com/lists/oss-security/2025/03/07/2 https://go.dev/cl/654697 https://go.dev/issue/71984 https://pkg.go.dev/vuln/GO-2025-3503

Share on: