CVE-2025-4673
MediumAdvisory
Published 11 Jun 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.8
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,771
- of 17,790 indexed, latest versions
- Container images
- 3,385
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Sensitive headers not cleared on cross-origin redirect in net/http
Carried by container images the latest versions of 2,771 of 17,790 indexed charts deploy, on 3,385 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+153 more | 1.23.10 | 3,385 |
- OSV records
- DEBIAN-CVE-2025-4673GO-2025-3751
- Also known as
- BIT-golang-2025-4673
Charts affected
2,771 by stars
Container images carrying it
3,385 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| grafana/ | 0dc5a246ab16 | stdlib | 1.23.10 | 3 |
| grafana/ | a0f881232a6f | stdlib | 1.23.10 | 3 |
| grafana/ | 58a6c186ce78 | stdlib | 1.23.10 | 3 |
| grafana/ | 626900031c4e | stdlib | 1.23.10 | 3 |
| groundnuty/ | c14d7271e401 | stdlib | 1.23.10 | 3 |
| hashicorp/ | fcb75f691c8b | stdlib | 1.23.10 | 3 |
| library/ | af96c680a7e1 | stdlib | 1.23.10 | 3 |
| library/ | b83efabe3e7d | stdlib | 1.23.10 | 3 |
| library/ | 3162a6ead070 | stdlib | 1.23.10 | 3 |
| library/ | 468d34fefd63 | stdlib | 1.23.10 | 3 |
| library/ | 5d2aa4a7b5f9 | stdlib | 1.23.10 | 3 |
| library/ | ffd1b50c522a | stdlib | 1.23.10 | 3 |
| library/ | c8bb255c3559 | stdlib | 1.23.10 | 3 |
| louislam/ | 917318f9d7be | stdlib | 1.23.10 | 3 |
| minio/ | bd11edda91f3 | stdlib | 1.23.10 | 3 |
| mintel/ | caf71cee7b9a | stdlib | 1.23.10 | 3 |
| natsio/ | b3359eeb10bf | stdlib | 1.23.10 | 3 |
| oryd/ | 2c93beb5e5f2 | stdlib | 1.23.10 | 3 |
| prom/ | d5155cfac40a | stdlib | 1.23.10 | 3 |
| prom/ | d8a61419b841 | stdlib | 1.23.10 | 3 |
| prom/ | 565ee8650122 | stdlib | 1.23.10 | 3 |
| prom/ | bfad037f95e5 | stdlib | 1.23.10 | 3 |
| prom/ | 0a9031142481 | stdlib | 1.23.10 | 3 |
| prom/ | 8305a33fb80a | stdlib | 1.23.10 | 3 |
| prom/ | 4e7a1f00b9b2 | stdlib | 1.23.10 | 3 |
| prom/ | d23aca343b86 | stdlib | 1.23.10 | 3 |
| rcdelacruz/ | 38007f358355 | stdlib | 1.23.10 | 3 |
| rss3/ | d1d2ae6efd05 | stdlib | 1.23.10 | 3 |
| signoz/ | fcc4a3288154 | stdlib | 1.23.10 | 3 |
| stakater/ | 83fef483d497 | stdlib | 1.23.10 | 3 |
| traefik/ | 200689790a0a | stdlib | 1.23.10 | 3 |
| tykio/ | 55b4d31c7a01 | stdlib | 1.23.10 | 3 |
| tykio/ | 1489b58f642b | stdlib | 1.23.10 | 3 |
| tykio/ | 205215b815a4 | stdlib | 1.23.10 | 3 |
| vikunja/ | ed1f3ed467fe | stdlib | 1.23.10 | 3 |
| gcr.io/ | 2a685a38dd01 | stdlib | 1.23.10 | 3 |
| ghcr.io/ | a27779ed1085 | stdlib | 1.23.10 | 3 |
| ghcr.io/ | b776dae45d08 | stdlib | 1.23.10 | 3 |
| ghcr.io/ | cf9b41e17b93 | stdlib | 1.23.10 | 3 |
| ghcr.io/ | a1bc133af84e | stdlib | 1.23.10 | 3 |
| public.ecr.aws/ | c88ea2979a49 | stdlib | 1.23.10 | 3 |
| public.ecr.aws/ | fefa9ee7256a | stdlib | 1.23.10 | 3 |
| quay.io/ | dd3f47d5a5e4 | stdlib | 1.23.10 | 3 |
| quay.io/ | aa4da00c5b96 | stdlib | 1.23.10 | 3 |
| quay.io/ | f0c6fba81a24 | stdlib | 1.23.10 | 3 |
| quay.io/ | 6545dac92173 | stdlib | 1.23.10 | 3 |
| quay.io/ | 2b6db27eaf3d | stdlib | 1.23.10 | 3 |
| quay.io/ | 2ff71ba65cd7 | stdlib | 1.23.10 | 3 |
| quay.io/ | 51f294c56842 | stdlib | 1.23.10 | 3 |
| quay.io/ | bc4aa22272ef | stdlib | 1.23.10 | 3 |