VDB
Sign up
MEDIUM4.4

GHSA-qxp5-gwg8-xv66

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Quick fix

GHSA-qxp5-gwg8-xv66 — golang.org/x/net: upgrade to the fixed version with the command below.

go get golang.org/x/net@v0.36.0

Details

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/net
Introduced in: 0Fixed in: 0.36.0
Fixgo get golang.org/x/net@v0.36.0

References