CVE Vulnerabilities

CVE-2025-47912

Published: Oct 29, 2025 | Modified: Jan 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: http://[::1]/. IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

Affected Software

NameVendorStart VersionEnd Version
GoGolang*1.24.8 (excluding)
GoGolang1.25.0 (including)1.25.2 (excluding)
Golang-1.23Ubuntuplucky*
Golang-1.24Ubuntuplucky*

References