HomeDefault status
unaffected
Any version before 1.25.8
affected
1.26.0-0 (semver) before 1.26.1
affected
Description
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Problem types
CWE-1286: Improper Validation of Syntactic Correctness of Input
Product status
Any version before 1.25.8
1.26.0-0 (semver) before 1.26.1
Credits
Masaki Hara (https://github.com/qnighy) of Wantedly
References
groups.google.com/g/golang-announce/c/EdhZqrQ98hk