CVE-2025-4673
MediumAdvisory
Published 11 Jun 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.8
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,769
- of 17,803 indexed, latest versions
- Container images
- 3,383
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Sensitive headers not cleared on cross-origin redirect in net/http
Carried by container images the latest versions of 2,769 of 17,803 indexed charts deploy, on 3,383 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+154 more | 1.23.10 | 3,383 |
- OSV records
- DEBIAN-CVE-2025-4673GO-2025-3751
- Also known as
- BIT-golang-2025-4673
Charts affected
2,769 by stars
Container images carrying it
3,383 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 794079a7f241 | stdlib | 1.23.10 | 1 |
| library/ | addb86c0c520 | stdlib | 1.23.10 | 1 |
| library/ | 0a5157f742d2 | stdlib | 1.23.10 | 1 |
| library/ | 104204dadedf | stdlib | 1.23.10 | 1 |
| library/ | 1489caffaedb | stdlib | 1.23.10 | 1 |
| library/ | 1957e3314f43 | stdlib | 1.23.10 | 1 |
| library/ | 2f603f8d3abe | stdlib | 1.23.10 | 1 |
| library/ | 5d47b7bb2546 | stdlib | 1.23.10 | 1 |
| library/ | 7d0228d19042 | stdlib | 1.23.10 | 1 |
| library/ | eda951fd29a8 | stdlib | 1.23.10 | 1 |
| library/ | f5af5a5ce17f | stdlib | 1.23.10 | 1 |
| library/ | f98ac9dd97b0 | stdlib | 1.23.10 | 1 |
| library/ | cab8944a33a1 | stdlib | 1.23.10 | 1 |
| library/ | dfa9ba46d14b | stdlib | 1.23.10 | 1 |
| librenms/ | 0920bc9117a8 | stdlib | 1.23.10 | 1 |
| librenms/ | 4f1f3d667cc7 | stdlib | 1.23.10 | 1 |
| lightstep/ | c800e05e1eff | stdlib | 1.23.10 | 1 |
| linuxserver/ | 241009026e6f | stdlib | 1.23.10 | 1 |
| linuxserver/ | 938810eca3d3 | stdlib | 1.23.10 | 1 |
| linuxserver/ | 45c5fe102ff3 | stdlib | 1.23.10 | 1 |
| linuxserver/ | b7f906899cd3 | stdlib | 1.23.10 | 1 |
| lishimeng/ | 3d5752dac834 | stdlib | 1.23.10 | 1 |
| lishimeng/ | c79a67657baf | stdlib | 1.23.10 | 1 |
| lishimeng/ | 3d00485e64dc | stdlib | 1.23.10 | 1 |
| lishimeng/ | 3e7d05ded625 | stdlib | 1.23.10 | 1 |
| lishimeng/ | 0970dfe5dc8f | stdlib | 1.23.10 | 1 |
| lishimeng/ | 8145c3dc83c8 | stdlib | 1.23.10 | 1 |
| lishimeng/ | 9b2f8be6c7d3 | stdlib | 1.23.10 | 1 |
| lishimeng/ | e0b8d2d8ca28 | stdlib | 1.23.10 | 1 |
| listmonk/ | bf3903d54a46 | stdlib | 1.23.10 | 1 |
| litestream/ | c5a1e1b01916 | stdlib | 1.23.10 | 1 |
| livekit/ | 1ab01641b366 | stdlib | 1.23.10 | 1 |
| livekit/ | ecf1409c75e0 | stdlib | 1.23.10 | 1 |
| livekit/ | 3602a85840d5 | stdlib | 1.23.10 | 1 |
| livekit/ | 8391fd1b834f | stdlib | 1.23.10 | 1 |
| lmierzwa/ | 3751e5eed656 | stdlib | 1.23.10 | 1 |
| lmierzwa/ | d417abe7ddb5 | stdlib | 1.23.10 | 1 |
| localstack/ | 9d278167f2b7 | stdlib | 1.23.10 | 1 |
| loeken/ | 4ce6abc553b3 | stdlib | 1.23.10 | 1 |
| loftsh/ | 310cc7d690f5 | stdlib | 1.23.10 | 1 |
| loftsh/ | 25deb9bd2683 | stdlib | 1.23.10 | 1 |
| loftsh/ | 023b13bf5898 | stdlib | 1.23.10 | 1 |
| logiqai/ | 65b996bc7bdc | stdlib | 1.23.10 | 1 |
| logiqai/ | f5b551bca98e | stdlib | 1.23.10 | 1 |
| logiqai/ | 798306811f2d | stdlib | 1.23.10 | 1 |
| logiqai/ | 3e149f6781b8 | stdlib | 1.23.10 | 1 |
| logiqai/ | 4a746ff04d6a | stdlib | 1.23.10 | 1 |
| longhornio/ | dca34321452c | stdlib | 1.23.10 | 1 |
| longhornio/ | ede61fe2a472 | stdlib | 1.23.10 | 1 |
| longhornio/ | 5875cef29348 | stdlib | 1.23.10 | 1 |