CVE-2025-4673 | Google Go up to 1.23.9/1.24.3 net-http Proxy-Authorization/Proxy-Authenticate cross-domain policy (Nessus ID 238043 / WID-SEC-2025-1205)
A vulnerability classified as problematic has been found in Google Go up to 1.23.9/1.24.3. The affected element is an unknown function of the component net-http. This manipulation of the argument Proxy-Authorization/Proxy-Authenticate causes permissive cross-domain policy with untrusted domains.
This vulnerability is tracked as CVE-2025-4673. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.