Vulnerability Report: GO-2025-3383

standard library

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.

Affected Packages

  • Path
    Go Versions
    Symbols
  • from go1.24.0-0 before go1.24.0-rc.2
    all symbols

Aliases

References

Credits

  • Juho Forsén of Mattermost

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL