The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Oct 31, 2025 | Oct 29, 2025 |
| Amazon Linux Ami 2 | — | Upgrade runc-debuginfoUpgrade containerdUpgrade golang-sharedUpgrade ecs-initUpgrade nerdctlUpgrade golist-debuginfoUpgrade docker-debuginfoUpgrade cni-pluginsUpgrade oci-add-hooks-debuginfoUpgrade cni-plugins-debuginfoUpgrade amazon-ssm-agentUpgrade golistUpgrade oci-add-hooksUpgrade cri-toolsUpgrade rclone-debuginfoUpgrade amazon-ecr-credential-helperUpgrade containerd-debuginfoUpgrade amazon-cloudwatch-agentUpgrade golang-binUpgrade nerdctl-debuginfoUpgrade soci-snapshotterUpgrade runfinch-finchUpgrade golang-testsUpgrade rcloneUpgrade runcUpgrade golang-srcUpgrade golang-docsUpgrade golangUpgrade containerd-stressUpgrade cri-tools-debuginfoUpgrade amazon-ecr-credential-helper-debuginfoUpgrade golang-miscUpgrade docker | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade cni-pluginsUpgrade golang-sharedUpgrade runcUpgrade runc-debuginfoUpgrade oci-add-hooks-debuginfoUpgrade golist-debuginfoUpgrade docker-debugsourceUpgrade golang-docsUpgrade runc-debugsourceUpgrade libcap-debuginfoUpgrade docker-debuginfoUpgrade cni-plugins-debugsourceUpgrade runfinch-finchUpgrade containerdUpgrade cni-plugins-debuginfoUpgrade amazon-ssm-agentUpgrade nerdctlUpgrade amazon-ecr-credential-helperUpgrade containerd-debuginfoUpgrade ecs-initUpgrade amazon-cloudwatch-agentUpgrade captree-debuginfoUpgrade containerd-stressUpgrade libcap-debugsourceUpgrade golistUpgrade captreeUpgrade containerd-stress-debuginfoUpgrade libcap-staticUpgrade libcap-develUpgrade golang-srcUpgrade libcapUpgrade containerd-debugsourceUpgrade oci-add-hooks-debugsourceUpgrade oci-add-hooksUpgrade golist-debugsourceUpgrade golang-miscUpgrade golang-binUpgrade golangUpgrade golang-testsUpgrade dockerUpgrade soci-snapshotter | Oct 31, 2025 | Oct 29, 2025 |
| Dell Idrac | — | Upgrade Dell iDRAC to the latest version | Jun 26, 2026 | Jun 25, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade golang-helpUpgrade golangUpgrade golang-devel | Mar 17, 2026 | Mar 16, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade golangUpgrade golang-helpUpgrade golang-devel | Mar 10, 2026 | Mar 10, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 29, 2025 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.4Upgrade Splunk Enterprise to version 9.2.12Upgrade Splunk Enterprise to version 10.2.1Upgrade Splunk Enterprise to version 9.4.8Upgrade Splunk Enterprise to version 9.3.9Upgrade Splunk Enterprise to version 10.0.3Upgrade Splunk Enterprise to version 9.3.10Upgrade Splunk Enterprise to version 9.4.9 | Jul 30, 2026 | Oct 29, 2025 |
| Suse | — | Upgrade go1.24-raceUpgrade go1.25Upgrade go1.24-docUpgrade go1.24Upgrade go1.25-raceUpgrade go1.25-doc | Dec 5, 2025 | Oct 11, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 29, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub