
Proof-of-concept for CVE-2025-22870 demonstrating HTTP proxy bypass in vulnerable versions (<0.36.0) of golang.org/x/net/http/httpproxy. Exploits improper IPv6 zone ID parsing to evade NO_PROXY restrictions, enabling proxy bypass and potential SSRF under misconfigured environments.
This Proof of Concept demonstrates the exploitation of CVE-2025-22870, a vulnerability in the golang.org/x/net/http/httpproxy package (prior to v0.36.0), which can be used to bypass HTTP proxy restrictions by abusing the way IPv6 zone identifiers are matched against NO_PROXY patterns.
golang.org/x/net/http/httpproxyWhen the NO_PROXY environment variable is set to restrict certain domains from being routed through a proxy (e.g., NO_PROXY=*.example.com), a specially crafted request to a host with an IPv6 zone ID (e.g., [::1%25.example.com]) may incorrectly match and avoid being proxied. This results in proxy bypass, which could allow Server-Side Request Forgery (SSRF) under certain conditions.
This vulnerability can be leveraged to send requests directly to internal or local services while evading configured proxies, even if domains were supposedly protected by NO_PROXY.
The PoC exploits a vulnerability in the golang.org/x/net/http/httpproxy package, specifically in the way it parses IPv6 zone identifiers when matching against NO_PROXY rules.
The payload used is:
[::1%25.example.com]:https://raw.githubusercontent.com/joshuaprovoste/cve-2025-22870/HEAD/7777
Due to the parsing bug in the vulnerable package, this address bypasses the proxy despite matching NO_PROXY.