- Description
- url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- Source
- security@golang.org
- NVD status
- Modified
- Products
- go
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
🔒 ELSA-2026-29702: Atualização IMPORTANTE do runc no Oracle Linux 9 corrige 3 CVEs (CVE-2026-25679, CVE-2026-32280, CVE-2026-32281). Saiba mais: -> https://t.co/IRF67Myv1o #Oracle https://t.co/WLfmq1SbNR
@Cezar_H_Linux
26 Jun 2026
74 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🟠 HIGH (CVSS 7.5) — CVE-2026-25679 Published: 2026-03-06 net/url: Incorrect parsing of IPv6 host literals in net/url 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 🔗 NVD: https://t.co/Usw58WfE9a 📚 References: • https://t.co/TKkOwOqYLM
@CVE2026COIN
22 Jun 2026
5 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2D293CC0-B163-4E62-B985-52FB6ECA64C5",
"versionEndExcluding": "1.25.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:1.26.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A40FE3CB-0D03-462B-8A19-4DF1920ABE82",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]