« Volver al listado

CVE-2025-22870

Estado: AplazadaMedia (4.4)—

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-22870",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-22870",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-18T16:31:16.493335Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "net/http",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.23.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.24.0-0",
              "lessThan": "1.24.1",
              "versionType": "semver"
            }
          ],
          "packageName": "net/http",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "envProxyFunc"
            },
            {
              "name": "ProxyFromEnvironment"
            }
          ]
        },
        {
          "vendor": "golang.org/x/net",
          "product": "golang.org/x/net/http/httpproxy",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.36.0",
              "versionType": "semver"
            }
          ],
          "packageName": "golang.org/x/net/http/httpproxy",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "config.useProxy"
            },
            {
              "name": "domainMatch.match"
            }
          ]
        },
        {
          "vendor": "golang.org/x/net",
          "product": "golang.org/x/net/proxy",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.36.0",
              "versionType": "semver"
            }
          ],
          "packageName": "golang.org/x/net/proxy",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "PerHost.dialerForRequest"
            },
            {
              "name": "PerHost.AddFromString"
            },
            {
              "name": "Dial"
            },
            {
              "name": "FromEnvironment"
            },
            {
              "name": "FromEnvironmentUsing"
            },
            {
              "name": "PerHost.Dial"
            },
            {
              "name": "PerHost.DialContext"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-03-12T19:15:38.310",
  "references": [
    {
      "url": "https://go.dev/cl/654697",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/71984",
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ",
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2025-3503",
      "source": "security@golang.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/03/07/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20250509-0007/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-115"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to \"*.example.com\", a request to \"[::1%25.example.com]:80` will incorrectly match and not be proxied."
    },
    {
      "lang": "es",
      "value": "La coincidencia de hosts con patrones de proxy puede tratar incorrectamente un ID de zona IPv6 como un componente de nombre de host. Por ejemplo, si la variable de entorno NO_PROXY se establece en \"*.example.com\", una solicitud a \"[::1%25.example.com]:80` coincidirá incorrectamente y no se procesará mediante proxy."
    }
  ],
  "lastModified": "2026-06-17T08:50:40.640",
  "sourceIdentifier": "security@golang.org"
}