Information disclosure in Go programming language - CVE-2025-4673
Published: June 7, 2025
Vulnerability identifier: #VU110251
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-4673
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to sensitive Proxy-Authorization and Proxy-Authenticate headers are not cleared on cross-origin redirect in net/http. A remote attacker can gain access to credentials passed via these headers.
Affected software
Go programming language
Arch Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
Engineering Lifecycle Management
IBM Observability with Instana
Netcool Operations Insight
IBM Maximo Application Suite
IBM Automation Decision Services
IBM Business Automation Workflow
Splunk Operator for Kubernetes Add-on
IBM Cloud Pak for Business Automation
watsonx Orchestrate Developer Edition
Storage Defender - Resiliency Service
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Business Automation Insights
watsonx.data
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
restic
restic-zsh-completion
restic-bash-completion
opentelemetry-collector (Red Hat package)
apptainer
golang
golang-help
golang-devel
golang-1.22 (Ubuntu package)
go1.23
go1.23-doc
go1.23-race
go1.23-openssl
go1.23-openssl-race
go1.23-openssl-doc
go1.23-openssl-debuginfo
delve
go
go-toolset
golang (Red Hat package)
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
go1.24-race
go1.24-doc
go1.24
go1.24-openssl
go1.24-openssl-doc
go1.24-openssl-race
go1.24-openssl-debuginfo
golang-shared
etcd
Arch Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
Engineering Lifecycle Management
IBM Observability with Instana
Netcool Operations Insight
IBM Maximo Application Suite
IBM Automation Decision Services
IBM Business Automation Workflow
Splunk Operator for Kubernetes Add-on
IBM Cloud Pak for Business Automation
watsonx Orchestrate Developer Edition
Storage Defender - Resiliency Service
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
IBM Business Automation Manager Open Editions
Business Automation Insights
watsonx.data
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
restic
restic-zsh-completion
restic-bash-completion
opentelemetry-collector (Red Hat package)
apptainer
golang
golang-help
golang-devel
golang-1.22 (Ubuntu package)
go1.23
go1.23-doc
go1.23-race
go1.23-openssl
go1.23-openssl-race
go1.23-openssl-doc
go1.23-openssl-debuginfo
delve
go
go-toolset
golang (Red Hat package)
golang-tests
golang-src
golang-misc
golang-docs
golang-bin
go1.24-race
go1.24-doc
go1.24
go1.24-openssl
go1.24-openssl-doc
go1.24-openssl-race
go1.24-openssl-debuginfo
golang-shared
etcd
How to mitigate CVE-2025-4673
Install updates from vendor's website.
Go programming language - addressed in versions 1.23.10, 1.24.4
Engineering Lifecycle Management - update to 1.3.0
IBM Observability with Instana - update to 1.0.302
watsonx Orchestrate Developer Edition - update to 1.13.0
Netcool Operations Insight - update to 1.6.15
Storage Defender - Resiliency Service - update to 2.0.18
watsonx.data - update to 2.3
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
IBM Business Automation Manager Open Editions - update to 9.3.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
restic - update to 0.12.1-2
restic-zsh-completion - update to 0.12.1-2
restic-bash-completion - update to 0.12.1-2
opentelemetry-collector (Red Hat package) - addressed in versions 0.127.0-2.el9_4, 0.127.0-2.el9_6, 0.127.0-3.el10_0
apptainer - update to 1.4.2-1.el9
golang - update to 1.21.4-33
golang-help - update to 1.21.4-33
golang-devel - update to 1.21.4-33
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.4, 1.22.2-2~22.04.3, 1.22.8-1ubuntu0.1
go1.23 - update to 1.23.10-150000.1.34.1
go1.23-doc - update to 1.23.10-150000.1.34.1
go1.23-race - update to 1.23.10-150000.1.34.1
go1.23-openssl - update to 1.23.12-150600.13.9.1
go1.23-openssl-race - update to 1.23.12-150600.13.9.1
go1.23-openssl-doc - update to 1.23.12-150600.13.9.1
go1.23-openssl-debuginfo - update to 1.23.12-150600.13.9.1
delve - update to 1.24.1-1.0.2
go - update to 1.24.4-1
go-toolset - update to 1.24.4-1
golang (Red Hat package) - addressed in versions 1.24.4-1.el9_6, 1.24.4-1.el10_0
golang-tests - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-src - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-misc - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-docs - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-bin - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang - addressed in versions 1.24.4-1.0.2, 1.24.8-1
go1.24-race - update to 1.24.4-150000.1.26.1
go1.24-doc - update to 1.24.4-150000.1.26.1
go1.24 - update to 1.24.4-150000.1.26.1
go1.24-openssl - update to 1.24.6-150600.13.9.1
go1.24-openssl-doc - update to 1.24.6-150600.13.9.1
go1.24-openssl-race - update to 1.24.6-150600.13.9.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
golang-shared - update to 1.24.8-1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
etcd - update to 3.4.14-10
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
Engineering Lifecycle Management - update to 1.3.0
IBM Observability with Instana - update to 1.0.302
watsonx Orchestrate Developer Edition - update to 1.13.0
Netcool Operations Insight - update to 1.6.15
Storage Defender - Resiliency Service - update to 2.0.18
watsonx.data - update to 2.3
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
IBM Maximo Application Suite - addressed in versions 8.10.33, 8.11.30, 9.0.19, 9.1.8
Splunk Enterprise - addressed in versions 9.2.12, 9.3.9, 9.3.10, 9.4.8, 9.4.9, 10.0.3, 10.0.4, 10.2.1
IBM Business Automation Manager Open Editions - update to 9.3.1
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Business Automation Workflow - addressed in versions 24.0.0-IF007, 24.0.1-IF005, 25.0.0-IF002
restic - update to 0.12.1-2
restic-zsh-completion - update to 0.12.1-2
restic-bash-completion - update to 0.12.1-2
opentelemetry-collector (Red Hat package) - addressed in versions 0.127.0-2.el9_4, 0.127.0-2.el9_6, 0.127.0-3.el10_0
apptainer - update to 1.4.2-1.el9
golang - update to 1.21.4-33
golang-help - update to 1.21.4-33
golang-devel - update to 1.21.4-33
golang-1.22 (Ubuntu package) - addressed in versions 1.22.2-2ubuntu0.4, 1.22.2-2~22.04.3, 1.22.8-1ubuntu0.1
go1.23 - update to 1.23.10-150000.1.34.1
go1.23-doc - update to 1.23.10-150000.1.34.1
go1.23-race - update to 1.23.10-150000.1.34.1
go1.23-openssl - update to 1.23.12-150600.13.9.1
go1.23-openssl-race - update to 1.23.12-150600.13.9.1
go1.23-openssl-doc - update to 1.23.12-150600.13.9.1
go1.23-openssl-debuginfo - update to 1.23.12-150600.13.9.1
delve - update to 1.24.1-1.0.2
go - update to 1.24.4-1
go-toolset - update to 1.24.4-1
golang (Red Hat package) - addressed in versions 1.24.4-1.el9_6, 1.24.4-1.el10_0
golang-tests - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-src - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-misc - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-docs - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang-bin - addressed in versions 1.24.4-1.0.2, 1.24.8-1
golang - addressed in versions 1.24.4-1.0.2, 1.24.8-1
go1.24-race - update to 1.24.4-150000.1.26.1
go1.24-doc - update to 1.24.4-150000.1.26.1
go1.24 - update to 1.24.4-150000.1.26.1
go1.24-openssl - update to 1.24.6-150600.13.9.1
go1.24-openssl-doc - update to 1.24.6-150600.13.9.1
go1.24-openssl-race - update to 1.24.6-150600.13.9.1
go1.24-openssl-debuginfo - update to 1.24.6-150600.13.9.1
golang-shared - update to 1.24.8-1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
etcd - update to 3.4.14-10
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
External References
Related Security Bulletins
- Arch Linux update for go
- Multiple vulnerabilities in Go programming language
- SUSE update for go1.24
- SUSE update for go1.23
- Ubuntu update for golang-1.22
- openEuler update for golang
- Red Hat Enterprise Linux 9 update for golang
- Red Hat Enterprise Linux 10 update for golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- openEuler update for etcd
- openEuler 24.03 LTS SP2 update for golang
- Anolis OS update for go-toolset:an8 module
- Fedora EPEL 9 update for apptainer
- openEuler 22.03 LTS SP4 update for restic
- openEuler 22.03 LTS SP3 update for restic
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- SUSE update for go1.24-openssl
- SUSE update for go1.23-openssl
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- Multiple vulnerabilities in IBM Observability with Instana
- Red Hat Enterprise Linux 10 update for opentelemetry-collector
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Business Automation Workflow
- IBM watsonx Orchestrate Developer Edition update for net/http
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Automation Decision Services
- Anolis OS update for golang
- IBM watsonx.data update for net/http
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Go
- Splunk Enterprise Security update for third-party components
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Engineering Lifecycle Management on Hybrid Cloud
- Multiple vulnerabilities in Splunk Enterprise
- Splunk Operator for Kubernetes Add-on update for third-party components