REDHAT-BUG-2445356: High severity go net/url vulnerability
Published Mar 6, 2026
·Updated
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Affected Software
1 affected component
go net/url
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Perform additional validation of the URL host/authority component before passing input to url.Parse; reject or sanitize URLs with invalid or malformed host/authority values to mitigate the insufficient validation in url.Parse.
Event History
Mar 6, 2026
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software