Wind River Support Network

HomeDefectsLIN1023-16676
Acknowledged

LIN1023-16676 : Security Advisory - go - CVE-2025-47912

Created: Oct 31, 2025    Updated: Nov 18, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.
Live chat
Online