Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-47912

Опубликовано: 29 окт. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

EPSS

Процентиль: 9%
0.00033
Низкий

5.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

msrc
3 месяца назад

Insufficient validation of bracketed IPv6 hostnames in net/url

CVSS3: 5.3
debian
3 месяца назад

The Parse function permits values other than IPv6 addresses to be incl ...

CVSS3: 5.3
github
3 месяца назад

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость функции Parse() компонента net-url языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 9%
0.00033
Низкий

5.3 Medium

CVSS3

Дефекты