Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-22870 PoC — HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Source
Associated Vulnerability
Title: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net (CVE-2025-22870)
Description:Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
Description
CVE-2025-22870
Readme
# CVE-2025-22870 – Proxy Bypass via IPv6 Zone Parsing in Go 🔐

### 🧠 Description:

Go's HTTP libraries (`net/http`, `x/net/proxy`, `httpproxy`) misinterpret IPv6 zone identifiers like `%25` in hostnames when processing `NO_PROXY` rules.
This allows an attacker to craft a hostname like `[::1%25.example.com]:80`, which wrongly matches `.example.com` and **bypasses the configured proxy**, sending the request directly.

---

### ⚠️ Severity:

* **CVSS 3.1**: 4.4 (Medium)
* Some distributions (like Amazon Linux) rate it higher, up to **6.5**, due to remote exploit potential.

---

### 🎯 Affected Components:

* **Go programming language**: versions before **1.24.1** and **1.23.7**
* **golang.org/x/net** modules (like `httpproxy`): before **v0.36.0**
* Linux distros packaging these versions, e.g., Ubuntu, Debian, Alpine, Amazon Linux, SUSE

---

### 🧨 Exploit Scenario:

An attacker could:

* Exploit the mismatch in proxy matching
* Perform **SSRF** (Server-Side Request Forgery)
* Reach internal services that should be protected by a proxy

---

### ✅ Mitigation Steps:

1. **Upgrade Go** to at least **1.24.1** or **1.23.7**
2. **Update x/net libraries** to **v0.36.0 or newer**
3. **Rebuild containers or software** using older Go versions
4. **Audit proxy bypass settings** (`NO_PROXY`) to detect misuse of `%25` and zone identifiers

---

### 🧩 Technical Insight:

* `%25` is the URL-encoded form of `%`, used in IPv6 zone identifiers like `[fe80::1%eth0]`.
* Go fails to sanitize this, causing misclassification in hostname matching logic.

---

### 📌 Summary:

While rated "medium", this vulnerability becomes more serious in environments relying on strict proxy rules (e.g., cloud environments, zero-trust networks). Immediate patching and review of `NO_PROXY` behavior are highly recommended.


---

### 🕷️ Vulnerability Details:


The PoC exploits a vulnerability in the `golang.org/x/net/http/httpproxy` package, specifically in the way it parses IPv6 zone identifiers when matching against `NO_PROXY` rules.


The payload used is:

```
[::1%25.example.com]:7777
```

---

### ⚠️ Disclaimer:

> This content is shared **for educational and informational purposes only** 🧠.
> Any demonstrations, examples, or technical descriptions provided are intended to help developers, system administrators, and security professionals understand the nature of the vulnerability and how to protect against it 🛡️.
> **Do not use this information for unauthorized or malicious activities.**
> Misuse of such knowledge may violate laws and lead to serious consequences 🚫.
> Always act ethically and within legal boundaries ⚖️.


File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →