Go standard library net/url

4 known vulnerabilities in Go standard library net/url, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-56860 CVSS 5.9 medium Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each…
  • CVE-2026-25679 CVSS 7.5 high url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
  • CVE-2025-61726 CVSS 7.5 high The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs…
  • CVE-2025-47912 CVSS 5.3 medium The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986…