Commit 90ce398
committed
fix: Only wrap IPv6 addresses in square brackets per RFC 3986
Fixes a bug where IPv4 addresses were incorrectly wrapped in square
brackets when constructing the Kubernetes API server URL in
inClusterConfig(). This causes URL parsing failures in Go 1.25.2+
due to stricter RFC 3986 enforcement introduced in CVE-2025-47912.
The previous implementation (added in commit 3a3a2bc) unconditionally
wrapped all IP addresses in brackets under the assumption that "IPv4
also works with square brackets". However, RFC 3986 specifies that only
IPv6 addresses should be enclosed in brackets, and recent Go versions
now enforce this requirement.
Changes:
- Use net.ParseIP() to detect IP address type
- Only wrap IPv6 addresses (when To4() returns nil) in brackets
- Leave IPv4 addresses unwrapped for RFC 3986 compliance
- Add comprehensive test coverage for IPv4, IPv6, and edge cases
Error before fix:
parse "https://[172.20.0.1]:443/version": invalid IPv6 host
After fix:
IPv4: https://172.20.0.1:443 (unwrapped)
IPv6: https://[2001:db8::1]:443 (wrapped)
Signed-off-by: ByteBaker <[email protected]>1 parent a9a1389 commit 90ce398
2 files changed
+104
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
528 | 528 | | |
529 | 529 | | |
530 | 530 | | |
531 | | - | |
532 | | - | |
533 | | - | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
534 | 536 | | |
535 | 537 | | |
536 | 538 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
7 | 8 | | |
8 | 9 | | |
9 | 10 | | |
| |||
216 | 217 | | |
217 | 218 | | |
218 | 219 | | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
219 | 318 | | |
220 | 319 | | |
221 | 320 | | |
| |||
0 commit comments