CVE detail
CVE-2025-22870
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://security.netapp.com/advisory/ntap-20250509-0007/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comMar 12, 2025, 7:15 PM - http://www.openwall.com/lists/oss-security/2025/03/07/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 12, 2025, 7:15 PM - https://pkg.go.dev/vuln/GO-2025-3503pkg.go.dev
No excerpt available.
Exploitpkg.go.devMar 12, 2025, 7:15 PM No excerpt available.
Vendor Advisorygroups.google.comMar 12, 2025, 7:15 PMNo excerpt available.
Vendor Advisorygo.devMar 12, 2025, 7:15 PM- https://go.dev/cl/654697go.dev
No excerpt available.
Vendor Advisorygo.devMar 12, 2025, 7:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42004CVSS 3.7 · Low
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted,…
- CVE-2026-12491CVSS 4.8 · Medium
A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientat…
- CVE-2025-68113CVSS 6.5 · Medium
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable repl…
- CVE-2025-55303CVSS 6.9 · Medium
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering…
- CVE-2025-54584CVSS 7.0 · High
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfil…
- CVE-2025-5826CVSS 6.3 · Medium
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT…