Skip to main content

CVE-2025-22870

CVE Details

Visit the official vulnerability details page for CVE-2025-22870 to learn more.

Initial Publication

03/12/2025

Last Update

05/09/2025

Third Party Dependency

golang.org/x/net

NIST CVE Summary

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

CVE Severity

4.4

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.