CVE-2026-25679
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- Published Mar 6, 2026
- CVSS 7.5 high
- 0.8% chance of exploitation in the next 30 days (EPSS)
- A fix is available
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.