CVE-2025-22870

Source
https://cve.org/CVERecord?id=CVE-2025-22870
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-22870.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-22870
Aliases
Downstream
AZL (21)
BELL (1)
CGA (5157)
CLEANSTART (21)
DEBIAN (1)
ECHO (1)
MGASA (2)
MINI (150)
OESA (1)
openSUSE (29)
ROOT (1)
SUSE (39)
UBUNTU (1)
Related
Withdrawn
2026-01-27T04:19:56Z
Published
2025-03-12T19:15:38Z
Modified
2026-09-12T18:26:46Z
Summary
[none]
Details

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

References

Affected packages