VDB
Sign up
MEDIUM6.5

GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

Quick fix

GHSA-5cv4-jp36-h3mw — golang.org/x/net: upgrade to the fixed version with the command below.

go get golang.org/x/net@v0.55.0

Details

In Go Net (`golang.org/x/net`) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/net
Introduced in: 0Fixed in: 0.55.0
Fixgo get golang.org/x/net@v0.55.0

References