CVE-2025-47912
Public on 2025-10-13
Modified on 2025-11-01
Description
net/url: insufficient validation of bracketed IPv6 hostnames
The Parse function permitted values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
The Parse function permitted values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | amazon-cloudwatch-agent | Pending Fix | ||
| Amazon Linux 2023 | amazon-cloudwatch-agent | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Core | amazon-ssm-agent | Pending Fix | ||
| Amazon Linux 2023 | amazon-ssm-agent | Pending Fix | ||
| Amazon Linux 2 - Core | cni-plugins | Pending Fix | ||
| Amazon Linux 2023 | cni-plugins | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | containerd | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | containerd | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | containerd | Pending Fix | ||
| Amazon Linux 2023 | containerd | Pending Fix | ||
| Amazon Linux 2 - Core | cri-tools | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | docker | Pending Fix | ||
| Amazon Linux 2023 | docker | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | ecs-init | Pending Fix | ||
| Amazon Linux 2023 | ecs-init | Pending Fix | ||
| Amazon Linux 2 - Core | golang | 2025-10-27 | ALAS2-2025-3042 | Fixed |
| Amazon Linux 2023 | golang | 2025-10-27 | ALAS2023-2025-1239 | Fixed |
| Amazon Linux 2 - Core | golang-github-cpuguy83-go-md2man | Pending Fix | ||
| Amazon Linux 2 - Core | golang-github-godbus-dbus | Pending Fix | ||
| Amazon Linux 2 - Core | golang-github-gorilla-context | Pending Fix | ||
| Amazon Linux 2 - Core | golang-github-kr-pty | Pending Fix | ||
| Amazon Linux 2 - Core | golang-github-syndtr-gocapability | Pending Fix | ||
| Amazon Linux 2 - Core | golist | Pending Fix | ||
| Amazon Linux 2023 | libcap | Pending Fix | ||
| Amazon Linux 2 - Core | nerdctl | Pending Fix | ||
| Amazon Linux 2023 | nerdctl | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Core | rclone | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | runc | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | runc | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | runc | Pending Fix | ||
| Amazon Linux 2023 | runc | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | runfinch-finch | Pending Fix | ||
| Amazon Linux 2023 | runfinch-finch | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | soci-snapshotter | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 8.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
| NVD | CVSSv3 | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |