CVE-2025-22870
# CVE-2025-22870 – Proxy Bypass via IPv6 Zone Parsing in Go 🔐
### 🧠 Description:
Go's HTTP libraries (`net/http`, `x/net/proxy`, `httpproxy`) misinterpret IPv6 zone identifiers like `%25` in hostnames when processing `NO_PROXY` rules.
This allows an attacker to craft a hostname like `[::1%25.example.com]:80`, which wrongly matches `.example.com` and **bypasses the configured proxy**, sending the request directly.
---
### ⚠️ Severity:
* **CVSS 3.1**: 4.4 (Medium)
* Some distributions (like Amazon Linux) rate it higher, up to **6.5**, due to remote exploit potential.
---
### 🎯 Affected Components:
* **Go programming language**: versions before **1.24.1** and **1.23.7**
* **golang.org/x/net** modules (like `httpproxy`): before **v0.36.0**
* Linux distros packaging these versions, e.g., Ubuntu, Debian, Alpine, Amazon Linux, SUSE
---
### 🧨 Exploit Scenario:
An attacker could:
* Exploit the mismatch in proxy matching
* Perform **SSRF** (Server-Side Request Forgery)
* Reach internal services that should be protected by a proxy
---
### ✅ Mitigation Steps:
1. **Upgrade Go** to at least **1.24.1** or **1.23.7**
2. **Update x/net libraries** to **v0.36.0 or newer**
3. **Rebuild containers or software** using older Go versions
4. **Audit proxy bypass settings** (`NO_PROXY`) to detect misuse of `%25` and zone identifiers
---
### 🧩 Technical Insight:
* `%25` is the URL-encoded form of `%`, used in IPv6 zone identifiers like `[fe80::1%eth0]`.
* Go fails to sanitize this, causing misclassification in hostname matching logic.
---
### 📌 Summary:
While rated "medium", this vulnerability becomes more serious in environments relying on strict proxy rules (e.g., cloud environments, zero-trust networks). Immediate patching and review of `NO_PROXY` behavior are highly recommended.
---
### 🕷️ Vulnerability Details:
The PoC exploits a vulnerability in the `golang.org/x/net/http/httpproxy` package, specifically in the way it parses IPv6 zone identifiers when matching against `NO_PROXY` rules.
The payload used is:
```
[::1%25.example.com]:7777
```
---
### ⚠️ Disclaimer:
> This content is shared **for educational and informational purposes only** 🧠.
> Any demonstrations, examples, or technical descriptions provided are intended to help developers, system administrators, and security professionals understand the nature of the vulnerability and how to protect against it 🛡️.
> **Do not use this information for unauthorized or malicious activities.**
> Misuse of such knowledge may violate laws and lead to serious consequences 🚫.
> Always act ethically and within legal boundaries ⚖️.
登录后查看神龙缓存的 POC 文件快照
登录查看