The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Oct 31, 2025 | Oct 29, 2025 |
| Amazon Linux Ami 2 | — | Upgrade cri-tools-debuginfoUpgrade amazon-ecr-credential-helper-debuginfoUpgrade golangUpgrade containerd-stressUpgrade golang-srcUpgrade dockerUpgrade nerdctl-debuginfoUpgrade golang-testsUpgrade runcUpgrade soci-snapshotterUpgrade golang-binUpgrade golang-docsUpgrade rcloneUpgrade runfinch-finchUpgrade golang-miscUpgrade cri-toolsUpgrade runc-debuginfoUpgrade containerd-debuginfoUpgrade rclone-debuginfoUpgrade amazon-ssm-agentUpgrade oci-add-hooksUpgrade containerdUpgrade golist-debuginfoUpgrade cni-plugins-debuginfoUpgrade cni-pluginsUpgrade golistUpgrade docker-debuginfoUpgrade oci-add-hooks-debuginfoUpgrade amazon-ecr-credential-helperUpgrade amazon-cloudwatch-agentUpgrade golang-sharedUpgrade nerdctlUpgrade ecs-init | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade oci-add-hooksUpgrade captreeUpgrade libcap-develUpgrade libcap-staticUpgrade oci-add-hooks-debugsourceUpgrade containerd-debugsourceUpgrade golang-miscUpgrade containerd-stress-debuginfoUpgrade libcapUpgrade golistUpgrade golang-srcUpgrade dockerUpgrade golang-testsUpgrade golangUpgrade golang-binUpgrade golist-debugsourceUpgrade soci-snapshotterUpgrade oci-add-hooks-debuginfoUpgrade docker-debugsourceUpgrade containerd-stressUpgrade amazon-ssm-agentUpgrade golist-debuginfoUpgrade cni-pluginsUpgrade runc-debuginfoUpgrade ecs-initUpgrade captree-debuginfoUpgrade runcUpgrade golang-sharedUpgrade amazon-cloudwatch-agentUpgrade nerdctlUpgrade containerdUpgrade cni-plugins-debugsourceUpgrade libcap-debuginfoUpgrade golang-docsUpgrade cni-plugins-debuginfoUpgrade libcap-debugsourceUpgrade containerd-debuginfoUpgrade amazon-ecr-credential-helperUpgrade runc-debugsourceUpgrade docker-debuginfoUpgrade runfinch-finch | Oct 31, 2025 | Oct 29, 2025 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Jun 26, 2026 | Jun 25, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade golang-develUpgrade golangUpgrade golang-help | Mar 17, 2026 | Mar 16, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade golang-helpUpgrade golangUpgrade golang-devel | Mar 10, 2026 | Mar 10, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 29, 2025 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.3Upgrade Splunk Enterprise to version 9.4.9Upgrade Splunk Enterprise to version 9.3.9Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 9.2.12Upgrade Splunk Enterprise to version 9.4.8 | Jul 30, 2026 | Oct 29, 2025 |
| Suse | — | Upgrade go1.25Upgrade go1.24-docUpgrade go1.24-raceUpgrade go1.24Upgrade go1.25-raceUpgrade go1.25-doc | Dec 5, 2025 | Oct 11, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub