CVE-2025-47912

MEDIUM5.3EPSS 0.02%

Insufficient validation of bracketed IPv6 hostnames in net/url

發布日:2025/10/29修改日:2026/5/15
也稱為:BIT-golang-2025-47912CGA-crxx-5xpf-m6mvGO-2025-4010

描述

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

受影響套件(6)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

參考連結(7)