Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
No PoCs from references.
- https://github.com/297855/ctnm
- https://github.com/297855/nwctbf
- https://github.com/8-cm/kube-dump
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/B1ack4sh/Blackash-CVE-2025-22870
- https://github.com/Eleson-Souza/security-scan-pipeline
- https://github.com/JoshuaProvoste/CVE-2025-22870
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/TAMULib/metadb-docker
- https://github.com/carabiner-dev/lab-vexable-repo
- https://github.com/djylb/nps
- https://github.com/fleaz/trivy-renderer
- https://github.com/kaisensan/desafio-girus-pick
- https://github.com/mycoool/nps
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/unikorn-cloud/releases