The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ecs-init | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade ecs-initUpgrade yq-debugsourceUpgrade yqUpgrade yq-debuginfo | Feb 20, 2026 | Feb 5, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 5, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.6Upgrade Splunk Enterprise to version 9.4.11Upgrade Splunk Enterprise to version 9.3.12Upgrade Splunk Enterprise to version 10.2.3 | Jul 30, 2026 | Feb 5, 2026 |
| Suse | — | Upgrade git-bug-fish-completionUpgrade git-bugUpgrade git-bug-zsh-completionUpgrade git-bug-bash-completion | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade lxc2 (Ubuntu Pro)Upgrade lxd (Ubuntu Pro)Upgrade juju (Ubuntu Pro)Upgrade golang-go.net-dev (Ubuntu Pro)Upgrade juju-2.0 (Ubuntu Pro)Upgrade lxd-tools (Ubuntu Pro)Upgrade adsys-windows (Ubuntu Pro)Upgrade golang-github-lxc-lxd-dev (Ubuntu Pro)Upgrade golang-golang-x-net-dev (Ubuntu Pro)Upgrade adsys (Ubuntu Pro)Upgrade lxd-client (Ubuntu Pro) | Mar 13, 2026 | Feb 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub