Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executablepath, @loaderpath, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.
End of life: 2/11/2025, Latest version: 1.22.12
End of life: 2/11/2025, Latest version: 1.22.12
End of life: 2/6/2024, Latest version: 1.20.14
End of life: 2/6/2024, Latest version: 1.20.14
End of life: 8/13/2024, Latest version: 1.21.13
End of life: 8/13/2024, Latest version: 1.21.13
End of life: 9/6/2023, Latest version: 1.19.13
End of life: 9/6/2023, Latest version: 1.19.13
End of life: 8/2/2022, Latest version: 1.17.13
End of life: 8/2/2022, Latest version: 1.17.13
End of life: 8/16/2021, Latest version: 1.15.15
End of life: 8/16/2021, Latest version: 1.15.15
End of life: 2/1/2023, Latest version: 1.18.10
End of life: 2/1/2023, Latest version: 1.18.10
End of life: 3/15/2022, Latest version: 1.16.15
End of life: 3/15/2022, Latest version: 1.16.15
End of life: 8/11/2020, Latest version: 1.13.15
End of life: 8/11/2020, Latest version: 1.13.15
End of life: 2/25/2020, Latest version: 1.12.17
End of life: 2/25/2020, Latest version: 1.12.17
End of life: 2/16/2021, Latest version: 1.14.15
End of life: 2/16/2021, Latest version: 1.14.15
End of life: 2/25/2019, Latest version: 1.10.8
End of life: 2/25/2019, Latest version: 1.10.8
End of life: 9/3/2019, Latest version: 1.11.13
End of life: 9/3/2019, Latest version: 1.11.13
https://groups.google.com/g/golang-announce/c/4t3lzH3I0eI/m/b42ImqrBAQAJ announces the release of Go versions 1.24.1 and 1.23.7, including a security fix for: net/http, x/net/proxy, x/net/http/httpproxy: proxy bypass using IPv6 zone IDs
Matching of hosts against proxy patterns could improperly treat an IPv6 zone ID as a hostname component. For example, when the NOPROXY environment variable was set to ".example.com", a request to "[::1%25.example.com]:80 would incorrectly match and not be proxied.
Thanks to Juho Forsén of Mattermost for reporting this issue.
This is CVE-2025-22870 and Go issue https://go.dev/issue/71984. -- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris