
Proof-of-concept for CVE-2025-22870 demonstrating HTTP proxy bypass in vulnerable versions (<0.36.0) of golang.org/x/net/http/httpproxy. Exploits improper IPv6 zone ID parsing to evade NO_PROXY restrictions, enabling proxy bypass and potential SSRF under misconfigured environments.
This Proof of Concept demonstrates the exploitation of CVE-2025-22870, a vulnerability in the golang.org/x/net/http/httpproxy package (prior to v0.36.0), which can be used to bypass HTTP proxy restrictions by abusing the way IPv6 zone identifiers are matched against NO_PROXY patterns.
golang.org/x/net/http/httpproxyWhen the NO_PROXY environment variable is set to restrict certain domains from being routed through a proxy (e.g., ), a specially crafted request to a host with an (e.g., ) may and avoid being proxied. This results in , which could allow under certain conditions.
NO_PROXY=*.example.com[::1%25.example.com]This vulnerability can be leveraged to send requests directly to internal or local services while evading configured proxies, even if domains were supposedly protected by NO_PROXY.
The PoC exploits a vulnerability in the golang.org/x/net/http/httpproxy package, specifically in the way it parses IPv6 zone identifiers when matching against NO_PROXY rules.
The payload used is:
[::1%25.example.com]:https://raw.githubusercontent.com/joshuaprovoste/cve-2025-22870/main/7777
Due to the parsing bug in the vulnerable package, this address bypasses the proxy despite matching NO_PROXY.