Input validation error in httpproxy and proxy - CVE-2025-22870
Published: March 30, 2025 / Updated: July 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to alter application's behavior.
The vulnerability exists due to insufficient validation of an IPv6 zone ID as a hostname component, when matching hosts against proxy patterns. For instance the NO_PROXY environment variable is set to "*.example.com", a request to
"[::1%25.example.com]:80` will incorrectly match and not be proxied. A remote attacker can alter application behavior and potentially gain access to sensitive information or functionality.
Affected software
proxy
SUSE Linux Enterprise Server 15 SP5
SUSE Manager Proxy 4.3
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and
SUSE Liberty Linux 9.6
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Liberty Linux 7
SUSE Liberty LTSS 7 for Oracle
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Linux Micro
SUSE Liberty Linux
SUSE Enterprise Storage
Fedora
SUSE Manager Client Tools for RHEL, Liberty and Clones
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
Development Tools Module
HPC Module
Containers Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Oracle Solaris
IBM Security QRadar Log Management AQL Plugin
IBM Concert Software
Netcool Operations Insight
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
IBM Spectrum Protect Plus
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
IBM MQ Operator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Business Automation Workflow
Db2 Intelligence Center
DB2 Data Management Console
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Maximo Application Suite - IoT Component
Maximo Application Suite - Visual Inspection Component
Robotic Process Automation for Cloud Pak
Business Automation Insights
Storage Protect Server
Db2 Big SQL
watsonx.data
Splunk Enterprise
Event Streams
golang-github-facebook-time
kappanhang
golang-x-perf
mgrctl-debuginfo
mgrctl
mgrctl-zsh-completion
mgrctl-bash-completion
scap-security-guide-redhat
firewalld-prometheus-config
golang-github-QubitProducts-exporter_exporter-debugsource
golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter-debuginfo
squashfuse-tools
squashfuse-devel
squashfuse-tools-debuginfo
squashfuse-debuginfo
squashfuse
libsquashfuse0-debuginfo
squashfuse-debugsource
libsquashfuse0
lw-cli
golang-github-openprinting-ipp-usb
prometheus-postgres_exporter
restic
golang-github-prometheus-alertmanager-debuginfo
golang-github-prometheus-alertmanager
alertmanager
kitty
ov
golang-github-lusitaniae-apache_exporter
golang-github-edoardottt-lit-bb-hack-tools
apptainer-debuginfo
apptainer-sle15_7
apptainer
apptainer-sle15_5
apptainer-leap
apptainer-sle15_6
golang-github-prometheus-prom2json
apptainer-sle16
podman-tui
containernetworking-plugins
containerd
opentofu
node-exporter
golang-github-prometheus-node_exporter-debuginfo
golang-github-prometheus-node_exporter
grpcurl
skopeo-zsh-completion
skopeo
skopeo-debuginfo
skopeo-bash-completion
skopeo-fish-completion
prometheus-podman-exporter
golang-devel
golang
golang-help
golang-1.22 (Ubuntu package)
go1.23-race
go1.23
go1.23-doc
go1.23-openssl-race
go1.23-openssl
go1.23-openssl-debuginfo
go1.23-openssl-doc
golang-bin
golang-shared
golang-docs
golang-misc
golang-src
golang-tests
go1.24-doc
go1.24-race
go1.24
cri-tools1.29
cri-tools1.31
cri-o1.31
rclone
doctl
ffuf
elemental-toolkit
cosign-bash-completion
cosign-debuginfo
cosign
cosign-zsh-completion
cosign-fish-completion
ignition-dracut-grub2
ignition
ignition-debuginfo
docker-compose
golang-github-prometheus-prometheus-debuginfo
golang-github-prometheus-prometheus
golang-github-prometheus
gh
python-simplejson
amazon-ssm-agent
git-lfs
helm-debuginfo
helm-fish-completion
helm-zsh-completion
helm-bash-completion
helm
warewulf4-overlay
warewulf4-overlay-slurm
warewulf4-overlay-rke2
warewulf4-reference-doc
warewulf4-dracut
warewulf4-man
warewulf4
yq
spacecmd
mgr-push
python2-mgr-push
python2-uyuni-common-libs
python2-rhnlib
python2-spacewalk-client-tools
spacewalk-client-tools
reposurgeon
incus
staticcheck
venv-salt-minion
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2025-22870
proxy - update to 0.36.0
IBM Security QRadar Log Management AQL Plugin - update to 1.1.3
IBM Concert Software - update to 2.0.0
Db2 Intelligence Center - update to 1.1.2.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
IBM Fusion HCI - update to 2.11.0
DB2 Data Management Console - update to 3.1.13.2
Guardium Data Security Center (GDSC) - addressed in versions 3.7.2, 3.8.5
Security QRadar EDR - update to 3.12.17
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.3
IBM Cloud Pak for Data Scheduling - update to 5.2.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.29, 8.8.26, 9.0.15, 9.1.6
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
Maximo Application Suite - Visual Inspection Component - update to 9.1.1
Event Streams - update to 12.2.1
IBM Spectrum Protect Plus - update to 10.1.17.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF004
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
IBM Automation Decision Services - update to 24.0.0.0.4
golang-github-facebook-time - update to 0^20251021gite970944-1.el9
kappanhang - update to 0-0.3.20250427gitdffb773.fc41
golang-x-perf - update to 0-0.28.20250326git02a15fd.fc41
mgrctl-debuginfo - update to 0.1.39-1.32.1
mgrctl - addressed in versions 0.1.39-1.32.1, 5.2.12-80002.3.12.4, 5.2.12-90002.3.12.1
mgrctl-zsh-completion - addressed in versions 0.1.39-1.32.1, 5.2.12-80002.3.12.4, 5.2.12-90002.3.12.1
mgrctl-bash-completion - addressed in versions 0.1.39-1.32.1, 5.2.12-80002.3.12.4, 5.2.12-90002.3.12.1
scap-security-guide-redhat - addressed in versions 0.1.79-80002.3.9.6, 0.1.79-90002.3.9.1, 0.1.80-1.44.1
firewalld-prometheus-config - update to 0.1-150100.4.26.2
golang-github-QubitProducts-exporter_exporter-debugsource - addressed in versions 0.4.0-1.9.1, 0.4.0-80002.3.6.6, 0.4.0-90002.3.6.4
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-1.9.1, 0.4.0-70002.3.6.2, 0.4.0-80002.3.6.6, 0.4.0-90002.3.6.4
golang-github-QubitProducts-exporter_exporter-debuginfo - addressed in versions 0.4.0-1.9.1, 0.4.0-80002.3.6.6, 0.4.0-90002.3.6.4
squashfuse-tools - update to 0.5.0-150600.3.2.1
squashfuse-devel - update to 0.5.0-150600.3.2.1
squashfuse-tools-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse - update to 0.5.0-150600.3.2.1
libsquashfuse0-debuginfo - update to 0.5.0-150600.3.2.1
squashfuse-debugsource - update to 0.5.0-150600.3.2.1
libsquashfuse0 - update to 0.5.0-150600.3.2.1
lw-cli - update to 0.7.0-3.fc43
golang-github-openprinting-ipp-usb - addressed in versions 0.9.30-1.fc41, 0.9.30-4.fc40
prometheus-postgres_exporter - addressed in versions 0.10.1-1.15.1, 0.10.1-70002.3.3.3, 0.10.1-80002.3.3.6, 0.10.1-90002.3.3.4
restic - update to 0.18.0-1.fc43
golang-github-prometheus-alertmanager-debuginfo - update to 0.26.0-150100.4.25.2
golang-github-prometheus-alertmanager - update to 0.26.0-150100.4.25.2
golang-github-prometheus-alertmanager - update to 0.28.1-1.fc43
alertmanager - update to 0.31.1-1.el9
kitty - update to 0.40.0-2.fc40
ov - update to 0.42.1-1.fc43
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.10-70002.3.9.3, 1.0.10-80002.3.9.6, 1.0.10-90002.3.9.4
IBM Observability with Instana - update to 1.0.295
golang-github-edoardottt-lit-bb-hack-tools - update to 1.3.5-4.fc43
apptainer-debuginfo - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_7 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer-leap - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer-sle15_6 - addressed in versions 1.3.6-150600.4.9.1, 1.4.5-150600.4.12.1
apptainer - addressed in versions 1.4.2-1.el8, 1.4.2-1.el9, 1.4.2-1.fc41
golang-github-prometheus-prom2json - update to 1.4.2-1.fc43
apptainer-sle16 - update to 1.4.5-150600.4.12.1
podman-tui - addressed in versions 1.5.0-1.el10_1, 1.5.0-1.fc41, 1.5.0-1.fc42, 1.5.0-2.el9
containernetworking-plugins - update to 1.5.1-2.fc40
containerd - update to 1.7.29-1.fc41
opentofu - addressed in versions 1.9.1-1.fc43, 1.10.3-1.el9
node-exporter - addressed in versions 1.9.1-1.fc43, 1.9.1-2.el9
golang-github-prometheus-node_exporter-debuginfo - update to 1.9.1-150100.3.35.2
golang-github-prometheus-node_exporter - addressed in versions 1.9.1-150100.3.35.2, 1.10.2-1.12.1, 1.10.2-70002.3.3.3, 1.10.2-80002.3.3.6, 1.10.2-90002.3.3.4
grpcurl - update to 1.9.3-1.fc43
skopeo-zsh-completion - update to 1.14.4-150300.11.22.1
skopeo - update to 1.14.4-150300.11.22.1
skopeo-debuginfo - update to 1.14.4-150300.11.22.1
skopeo-bash-completion - update to 1.14.4-150300.11.22.1
skopeo-fish-completion - update to 1.14.4-150300.11.22.1
prometheus-podman-exporter - addressed in versions 1.16.0-1.el9, 1.16.0-1.fc41, 1.16.0-1.fc42
golang-devel - update to 1.21.4-32
golang - update to 1.21.4-32
golang-help - update to 1.21.4-32
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.4, 1.22.2-2~22.04.3, 1.22.8-1ubuntu0.1
go1.23-race - update to 1.23.7-150000.1.24.1
go1.23 - update to 1.23.7-150000.1.24.1
go1.23-doc - update to 1.23.7-150000.1.24.1
golang - addressed in versions 1.23.8-1.fc40, 1.23.8-1.fc41
go1.23-openssl-race - addressed in versions 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1
go1.23-openssl - addressed in versions 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1
go1.23-openssl-debuginfo - addressed in versions 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1
go1.23-openssl-doc - addressed in versions 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1
golang-bin - update to 1.24.0-10
golang - update to 1.24.0-10
golang-shared - update to 1.24.0-10
golang-docs - update to 1.24.0-10
golang-misc - update to 1.24.0-10
golang-src - update to 1.24.0-10
golang-tests - update to 1.24.0-10
go1.24-doc - update to 1.24.1-150000.1.12.1
go1.24-race - update to 1.24.1-150000.1.12.1
go1.24 - update to 1.24.1-150000.1.12.1
cri-tools1.29 - addressed in versions 1.29.0-11.fc41, 1.29.0-11.fc42, 1.29.0-11.fc43
cri-tools1.31 - update to 1.31.1-4.fc43
cri-o1.31 - update to 1.31.7-1.fc43
rclone - addressed in versions 1.70.2-1.fc43, 1.70.3-1.el9
doctl - update to 1.132.0-1.fc43
ffuf - addressed in versions 2.1.0-1.fc43, 2.1.0-1.fc44
elemental-toolkit - update to 2.2.3-slfo.1.1_1.1
cosign-bash-completion - update to 2.5.0-150400.3.27.1
cosign-debuginfo - update to 2.5.0-150400.3.27.1
cosign - update to 2.5.0-150400.3.27.1
cosign-zsh-completion - update to 2.5.0-150400.3.27.1
cosign-fish-completion - update to 2.5.0-150400.3.27.1
ignition-dracut-grub2 - update to 2.14.0-150400.9.9.1
ignition - update to 2.14.0-150400.9.9.1
ignition-debuginfo - update to 2.14.0-150400.9.9.1
docker-compose - update to 2.36.1-1.fc43
golang-github-prometheus-prometheus-debuginfo - update to 2.53.4-150100.4.26.2
golang-github-prometheus-prometheus - update to 2.53.4-150100.4.26.2
golang-github-prometheus - update to 2.55.1-1.fc43
gh - update to 2.72.0-1.fc43
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
IBM MQ Operator - addressed in versions 3.2.12, 3.5.3, 9.4.2.1-r2
python-simplejson - update to 3.3.1-70002.1.3.1
amazon-ssm-agent - addressed in versions 3.3.1611.0-4.39.1, 3.3.1611.0-150000.5.23.1
git-lfs - update to 3.7.1-1.fc41
helm-debuginfo - update to 3.17.2-150000.1.44.1
helm-fish-completion - update to 3.17.2-150000.1.44.1
helm-zsh-completion - update to 3.17.2-150000.1.44.1
helm-bash-completion - update to 3.17.2-150000.1.44.1
helm - update to 3.17.2-150000.1.44.1
warewulf4-overlay - update to 4.6.0-150500.6.34.1
warewulf4-overlay-slurm - update to 4.6.0-150500.6.34.1
warewulf4-overlay-rke2 - update to 4.6.0-150500.6.34.1
warewulf4-reference-doc - update to 4.6.0-150500.6.34.1
warewulf4-dracut - update to 4.6.0-150500.6.34.1
warewulf4-man - update to 4.6.0-150500.6.34.1
warewulf4 - update to 4.6.0-150500.6.34.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.18.3
yq - addressed in versions 4.47.1-1.fc41, 4.47.1-2.fc41
spacecmd - addressed in versions 5.0.16-1.61.1, 5.2.8-70002.3.12.1, 5.2.8-80002.3.12.4, 5.2.8-90002.3.12.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
mgr-push - update to 5.2.4-70002.3.9.2
python2-mgr-push - update to 5.2.4-70002.3.9.2
python2-uyuni-common-libs - update to 5.2.5-70002.3.6.1
python2-rhnlib - update to 5.2.5-70002.3.9.1
python2-spacewalk-client-tools - update to 5.2.6-70002.3.9.1
spacewalk-client-tools - update to 5.2.6-70002.3.9.1
reposurgeon - update to 5.3-1.fc42
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
Storage Protect Server - update to 8.1.27.100
Db2 Big SQL - update to 8.2
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
staticcheck - update to 2026.1-1.el9
venv-salt-minion - addressed in versions 3006.0-70002.5.19.1, 3006.0-80002.5.19.1, 3006.0-90002.5.19.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Security restrictions bypass in Go proxy component
- Fedora 40 update for kitty
- Fedora 41 update for golang-github-openprinting-ipp-usb
- Fedora 43 update for golang-github-edoardottt-lit-bb-hack-tools
- Fedora 43 update for cri-tools1.31
- Fedora 43 update for cri-tools1.29
- Fedora 42 update for cri-tools1.29
- Fedora 41 update for cri-tools1.29
- Fedora 40 update for containernetworking-plugins
- SUSE update for go1.24
- SUSE update for go1.23
- SUSE update for amazon-ssm-agent
- SUSE update for amazon-ssm-agent
- SUSE update for apptainer
- SUSE update for helm
- SUSE update for skopeo
- SUSE update for warewulf4
- Fedora 43 update for cri-o1.31
- Fedora 41 update for podman-tui
- Fedora EPEL 10.1 update for podman-tui
- Fedora 42 update for podman-tui
- Fedora EPEL 9 update for prometheus-podman-exporter
- Fedora 41 update for prometheus-podman-exporter
- Fedora 42 update for prometheus-podman-exporter
- Fedora EPEL 9 update for podman-tui
- Fedora 41 update for golang
- Fedora 40 update for golang
- Oracle Solaris update for third-party components
- Fedora 40 update for golang-github-openprinting-ipp-usb
- SUSE update for cosign
- openEuler update for golang
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Fedora 41 update for kappanhang
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM Business Automation Workflow
- Fedora 41 update for incus
- Fedora 42 update for incus
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Fedora 43 update for docker-compose
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- SUSE update for go1.23-openssl
- Multiple vulnerabilities in IBM Guardium Data Security Center
- SUSE update for elemental-toolkit
- Input validation error in IBM CloudPak for Data Scheduling Service
- Fedora 41 update for golang-x-perf
- SUSE update for golang-github-prometheus-node_exporter
- SUSE update for golang-github-prometheus-prometheus
- SUSE update for golang-github-prometheus-alertmanager
- SUSE update for ignition
- Ubuntu update for golang-1.22
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Fedora 43 update for opentofu
- Fedora 43 update for doctl
- Fedora 43 update for ov
- Fedora 43 update for rclone
- Fedora 43 update for node-exporter
- Fedora 43 update for golang-github-prometheus-alertmanager
- Fedora 43 update for restic
- Fedora 43 update for lw-cli
- IBM watsonx.data update for golang httpproxy
- Fedora 43 update for golang-github-prometheus-prom2json
- Fedora 43 update for golang-github-prometheus
- Fedora 43 update for grpcurl
- Fedora 42 update for reposurgeon
- Fedora EPEL 9 update for opentofu
- Fedora EPEL 9 update for node-exporter
- Fedora EPEL 9 update for rclone
- Multiple vulnerabilities in IBM Automation Decision Services
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Go HTTP Proxy
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Fedora EPEL 9 update for apptainer
- Fedora 41 update for apptainer
- Fedora EPEL 8 update for apptainer
- Fedora 44 update for ffuf
- Fedora 43 update for ffuf
- Multiple vulnerabilities in IBM Concert Software
- IBM Watson Discovery update for go httpproxy
- Fedora 41 update for yq
- Fedora 41 update for yq
- SUSE update for go1.23-openssl
- Multiple vulnerabilities in IBM Fusion
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2 Intelligence Center
- IBM Maximo Application Suite - Visual Inspection Component update for golang.org/x/net
- Multiple vulnerabilities in IBM Security QRadar Log Management AQL Plugin
- Fedora EPEL 9 update for golang-github-facebook-time
- Anolis OS update for golang
- Fedora 41 update for containerd
- Fedora 41 update for git-lfs
- IBM Storage Protect Server update for Golang net library
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- IBM Db2 Big SQL on Cloud Pak for Data update for golang.org/x/net
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM Business Automation Insights
- Fedora EPEL 9 update for staticcheck
- IBM Event Streams update for golang.org/x/net/proxy
- Fedora EPEL 9 update for alertmanager
- Multiple vulnerabilities in Splunk Enterprise
- SUSE update for apptainer
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- SUSE update for Security update 5.0.8 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.4 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.4 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.4 for Multi-Linux Manager Client Tools
- Fedora 43 update for gh