Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4gw-w5jq-g9jh

Опубликовано: 12 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

golang.org/x/net/html has a Quadratic Parsing Complexity issue

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to Denial of Service (DoS) if an attacker provides specially crafted HTML content.

Пакеты

Наименование

golang.org/x/net/html

go
Затронутые версииВерсия исправления

< 0.45.0

0.45.0

EPSS

Процентиль: 4%
0.00016
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-407

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

CVSS3: 5.3
redhat
2 месяца назад

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

CVSS3: 5.3
nvd
2 месяца назад

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

CVSS3: 5.3
debian
2 месяца назад

The html.Parse function in golang.org/x/net/html has quadratic parsing ...

CVSS3: 5.3
redos
10 дней назад

Уязвимость golang-x-net

EPSS

Процентиль: 4%
0.00016
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-407