CVE-2025-22870 is an improper input-validation vulnerability in the Go x/net proxy library's host-pattern matching. An IPv6 zone identifier can be incorrectly interpreted as a hostname component when evaluating proxy exclusions. A crafted IPv6 destination containing a zone identifier that matches a configured NO_PROXY hostname pattern can therefore cause a request to bypass the configured proxy.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-22870, a vulnerability in Go's HTTP libraries that allows proxy bypass via improper parsing of IPv6 zone identifiers in NO_PROXY rules. The repository consists of a single Go source file (CVE-2025-22870.go) and a detailed README.md. The exploit sets up environment variables to configure a proxy and NO_PROXY rule, then sends an HTTP request to an endpoint using a specially crafted IPv6 address with a zone identifier encoded as '%25'. This request is intended to bypass the proxy due to the vulnerability, demonstrating the risk of SSRF and unauthorized internal access. The code is concise and serves as a clear demonstration of the issue, targeting Go versions before 1.24.1/1.23.7 and x/net libraries before v0.36.0. No additional payloads or weaponization are present; the exploit is a minimal PoC for research and awareness.
This repository contains a Proof of Concept (PoC) exploit for CVE-2025-22870, a vulnerability in the Go package golang.org/x/net/http/httpproxy (versions prior to 0.36.0). The exploit demonstrates how an attacker can bypass HTTP proxy restrictions by crafting a request to an IPv6 address with a zone ID (e.g., [::1%25.example.com]:7777). The main Go file sets up HTTP_PROXY and NO_PROXY environment variables, then issues a GET request to the crafted endpoint. Due to improper parsing of the IPv6 zone ID, the request is not routed through the proxy as intended, potentially enabling SSRF or unauthorized access to internal resources. The repository consists of a single exploit file (CVE-2025-22870.go) and a detailed README explaining the vulnerability, impact, and usage.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go proxy-bypass flaw in which host matching for NO_PROXY patterns improperly interprets an IPv6 zone ID as part of the hostname, potentially causing requests that should use a proxy to bypass it.
Proxy-bypass vulnerability in golang.org/x/net/proxy using IPv6 zone IDs.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.