{"id":"CVE-2025-22870","aliases":["GHSA-qxp5-gwg8-xv66","GO-2025-3503"],"url":"https://o3.security/vulnerability/CVE-2025-22870","summary":"HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net","details":"Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to \"*.example.com\", a request to \"[::1%25.example.com]:80` will incorrectly match and not be proxied.","published":"2025-03-12T19:15:38Z","modified":"2026-07-31T18:30:18.994950424Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"golang.org/x/net","fixedVersion":"0.36.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250509-0007/"},{"type":"WEB","url":"https://go.dev/cl/654697"},{"type":"WEB","url":"https://go.dev/issue/71984"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3503"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/07/2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-31T18:30:18.994950424Z"}}