The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-init | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade yq-debugsourceUpgrade ecs-initUpgrade yqUpgrade yq-debuginfo | Feb 20, 2026 | Feb 5, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 5, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.6Upgrade Splunk Enterprise to version 10.2.3Upgrade Splunk Enterprise to version 9.4.11Upgrade Splunk Enterprise to version 9.3.12 | Jul 30, 2026 | Feb 5, 2026 |
| Suse | — | Upgrade git-bugUpgrade git-bug-fish-completionUpgrade git-bug-zsh-completionUpgrade git-bug-bash-completion | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade adsys (Ubuntu Pro)Upgrade golang-go.net-dev (Ubuntu Pro)Upgrade lxc2 (Ubuntu Pro)Upgrade golang-golang-x-net-dev (Ubuntu Pro)Upgrade juju-2.0 (Ubuntu Pro)Upgrade golang-github-lxc-lxd-dev (Ubuntu Pro)Upgrade lxd-tools (Ubuntu Pro)Upgrade juju (Ubuntu Pro)Upgrade adsys-windows (Ubuntu Pro)Upgrade lxd-client (Ubuntu Pro)Upgrade lxd (Ubuntu Pro) | Mar 13, 2026 | Feb 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub