CVE-2026-25679 is a high-severity vulnerability affecting the Go language's url.Parse function, which insufficiently validates host/authority components and accepts invalid URLs. This flaw can impact applications and services built with Go, including those deployed in environments like AWS Lambda. Rated with a CVSS score of 7.5 (HIGH), it is remotely exploitable with low complexity and no required user interaction, primarily posing a high risk to system availability. While there is no known public exploit code or evidence of active exploitation in the wild (KEV: No), the vulnerability is on a "Hot List: Active" and has garnered significant community attention, including vendor patching efforts for Go versions and AWS Lambda base images.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.25.8CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
1.26.0CPE matchmatch criteria | cpe:2.3:a:golang:go:1.26.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.