Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25680

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

A flaw was found in golang.org/x/net/html. A remote attacker could provide specially crafted HTML, which, when parsed by the affected component, would consume excessive CPU resources. This could lead to a Denial of Service (DoS) condition, making the system unavailable to legitimate users.

Отчет

Red Hat rates this issue as Moderate with RH CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). A flaw was found in golang.org/x/net/html where parsing crafted HTML can consume excessive CPU time, leading to denial of service. Exploitation requires user interaction (a victim application parsing attacker-controlled HTML). Most Red Hat products that bundle golang.org/x/net do not use the html parser to process untrusted HTML in their supported execution paths.

Меры по смягчению последствий

Update affected Go applications to use golang.org/x/net version 0.55.0 or later. As a workaround, do not use golang.org/x/net/html to parse untrusted HTML content, or enforce timeouts on HTML parsing operations. Applications that do not parse arbitrary HTML are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-rhel9-operatorFix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2480760golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing

EPSS

Процентиль: 25%
0.00326
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

CVSS3: 6.5
nvd
3 месяца назад

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

CVSS3: 6.5
msrc
2 месяца назад

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

CVSS3: 6.5
debian
3 месяца назад

Parsing arbitrary HTML can consume excessive CPU time, possibly leadin ...

CVSS3: 6.5
github
2 месяца назад

Go Net HTML parser is vulnerable to denial of service

EPSS

Процентиль: 25%
0.00326
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-25680