CVE-2025-4673

Name
CVE-2025-4673
Description
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security@golang.org https://go.dev/cl/679257
security@golang.org https://go.dev/issue/73816
security@golang.org https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A
security@golang.org https://pkg.go.dev/vuln/GO-2025-3751

Match rules

CPE URI Source package Min version Max version
net/http >= 0 < 1.23.10
net/http >= 1.24.0-0 < 1.24.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
go edge-community 1.24.4-r0 fossdd <fossdd@pwned.life> fixed
go 3.22-community 1.24.4-r0 None fixed