CVE-2025-4673
MediumAdvisory
Published 11 Jun 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.8
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,769
- of 17,803 indexed, latest versions
- Container images
- 3,383
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Sensitive headers not cleared on cross-origin redirect in net/http
Carried by container images the latest versions of 2,769 of 17,803 indexed charts deploy, on 3,383 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+154 more | 1.23.10 | 3,383 |
- OSV records
- DEBIAN-CVE-2025-4673GO-2025-3751
- Also known as
- BIT-golang-2025-4673
Charts affected
2,769 by stars
Container images carrying it
3,383 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ntakashi/ | 4171ec641120 | stdlib | 1.23.10 | 1 |
| nvidia/ | 91b20b66d1cd | stdlib | 1.23.10 | 1 |
| oamdev/ | 1bcae00bd7b0 | stdlib | 1.23.10 | 1 |
| odavid/ | e7ab3bbc948e | stdlib | 1.23.10 | 1 |
| ofekmeister/ | 30d70fa9211b | stdlib | 1.23.10 | 1 |
| offchainlabs/ | e95865866129 | stdlib | 1.23.10 | 1 |
| okgolove/ | 974d2e5eb150 | stdlib | 1.23.10 | 1 |
| okteto/ | 57cd51176538 | stdlib | 1.23.10 | 1 |
| oliver006/ | 04d958d209ab | stdlib | 1.23.10 | 1 |
| oliver006/ | 120f7ec77293 | stdlib | 1.23.10 | 1 |
| oliver006/ | d55e056987af | stdlib | 1.23.10 | 1 |
| oliver006/ | d98e6db8094f | stdlib | 1.23.10 | 1 |
| olliai/ | a470d96525e4 | stdlib | 1.23.10 | 1 |
| olliai/ | 5716f2a8bd4c | stdlib | 1.23.10 | 1 |
| opea/ | 2bee4eb66f3e | stdlib | 1.23.10 | 1 |
| opea/ | 3ef121f34610 | stdlib | 1.23.10 | 1 |
| opea/ | 7f854e9bffaf | stdlib | 1.23.10 | 1 |
| opea/ | 514af17c495c | stdlib | 1.23.10 | 1 |
| openbas/ | a277796d9724 | golang-1.19 stdlib | no fix listed 1.23.10 | 1 |
| opencord/ | 0d693ba85fd6 | stdlib | 1.23.10 | 1 |
| opencsghq/ | 41cba9c366f1 | stdlib | 1.23.10 | 1 |
| opencsghq/ | 1cb36b49151e | stdlib | 1.23.10 | 1 |
| opencsghq/ | bdd2c58b9744 | stdlib | 1.23.10 | 1 |
| opencsghq/ | de15437db41b | stdlib | 1.23.10 | 1 |
| opendatacube/ | 120457ffcd69 | stdlib | 1.23.10 | 1 |
| openebs/ | 4f41dd782761 | stdlib | 1.23.10 | 1 |
| openenergyprojects/ | 58990f24fb25 | stdlib | 1.23.10 | 1 |
| openfga/ | 5e94966c11df | stdlib | 1.23.10 | 1 |
| openkruise/ | d3c6d69d2c39 | stdlib | 1.23.10 | 1 |
| openkruise/ | 0482722b4e56 | stdlib | 1.23.10 | 1 |
| openkruise/ | f81ae78a36a4 | stdlib | 1.23.10 | 1 |
| openkruise/ | a75e6739ea7d | stdlib | 1.23.10 | 1 |
| openkruise/ | a8108f771287 | stdlib | 1.23.10 | 1 |
| openmined/ | d11524a3854a | stdlib | 1.23.10 | 1 |
| openmined/ | 3a4144c0bb82 | stdlib | 1.23.10 | 1 |
| opennms/ | 88869082a14f | stdlib | 1.23.10 | 1 |
| openpolicyagent/ | b7b4d7cfdd52 | stdlib | 1.23.10 | 1 |
| openpolicyagent/ | 77bc9bf3d163 | stdlib | 1.23.10 | 1 |
| openpolicyagent/ | 6a58dea59933 | stdlib | 1.23.10 | 1 |
| openproject/ | 734743d11094 | stdlib | 1.23.10 | 1 |
| openruntimes/ | 2228f186dcbb | stdlib | 1.23.10 | 1 |
| opensearchproject/ | 43b0cdaf26ed | stdlib | 1.23.10 | 1 |
| opsgenie/ | ecb246e4d260 | stdlib | 1.23.10 | 1 |
| optimizely/ | 9d0096cabd63 | stdlib | 1.23.10 | 1 |
| oranhack7/ | c6453942223f | stdlib | 1.23.10 | 1 |
| orbitalreg/ | 45f2620337af | stdlib | 1.23.10 | 1 |
| oryd/ | b94007e19a1f | stdlib | 1.23.10 | 1 |
| oryd/ | 8f15006a080d | stdlib | 1.23.10 | 1 |
| otel/ | 9e36620d6c2c | stdlib | 1.23.10 | 1 |
| otel/ | ee9da0b08d83 | stdlib | 1.23.10 | 1 |