CVE-2025-47912
BaseFortify
Publication date: 2025-10-29
Last updated on: 2025-11-04
Assigner: Go Project
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| golang | go | From 1.25.0 (inc) to 1.25.2 (inc) |
| golang | go | 1.25.2 |
| golang | go | 1.24.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs because the Parse function allows values other than IPv6 addresses to be enclosed in square brackets within the host component of a URL. According to RFC 3986, only IPv6 addresses should be enclosed in square brackets in the host part of a URL, while IPv4 addresses and hostnames must not be enclosed this way. The Parse function does not enforce this rule, which can lead to improper URL parsing.
How can this vulnerability impact me? :
This vulnerability can lead to incorrect parsing of URLs, potentially causing security issues such as bypassing input validation, misrouting of network requests, or other unexpected behavior in applications that rely on strict URL parsing. This could be exploited to manipulate how URLs are interpreted, possibly leading to security risks.