CVE-2025-47912

CWE-12869 documents8 sources
Severity
5.3MEDIUM
EPSS
0.0%
top 93.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateOct 30

Description

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

Gostdlib1.25.01.25.2+1
NVDgolang/go1.25.01.25.2+1
CVEListV5go_standard_library/net/url1.25.01.25.2+1
Debiangolang-1.24< 1.24.8-1
Debiangolang-1.25< 1.25.2-1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-447v-2qg4-h8hc: The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL2025-10-30
CVEList
Insufficient validation of bracketed IPv6 hostnames in net/url2025-10-29
OSV
CVE-2025-47912: The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL2025-10-29
OSV
Insufficient validation of bracketed IPv6 hostnames in net/url2025-10-29

📋Vendor Advisories

3
Red Hat
net/url: Insufficient validation of bracketed IPv6 hostnames in net/url2025-10-29
Microsoft
Insufficient validation of bracketed IPv6 hostnames in net/url2025-10-14
Debian
CVE-2025-47912: golang-1.15 - The Parse function permits values other than IPv6 addresses to be included in sq...2025

💬Community

1
Bugzilla
CVE-2025-47912 net/url: Insufficient validation of bracketed IPv6 hostnames in net/url2025-10-29