Описание
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-golang-x-net | fixed | 1:0.55.0-1 | package | |
| golang-golang-x-net | no-dsa | trixie | package | |
| golang-golang-x-net | postponed | bookworm | package | |
| golang-golang-x-net | postponed | bullseye | package |
Примечания
https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
https://github.com/golang/go/issues/79573
Связанные уязвимости
CVSS3: 6.5
ubuntu
3 месяца назад
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVSS3: 6.5
redhat
3 месяца назад
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVSS3: 6.5
nvd
3 месяца назад
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVSS3: 6.5
msrc
2 месяца назад
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVSS3: 6.5
github
2 месяца назад
Go Net HTML parser is vulnerable to denial of service