CVE-2025-47912
Severity
5.3MEDIUM
EPSS
0.0%
top 93.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 29
Latest updateOct 30
Description
The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-447v-2qg4-h8hc: The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL↗2025-10-30
OSV▶
CVE-2025-47912: The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL↗2025-10-29
📋Vendor Advisories
3💬Community
1Bugzilla
▶