VDB
Sign up
HIGH7.5

GHSA-83g2-8m93-v3w7

golang.org/x/net/html Infinite Loop vulnerability

Quick fix

GHSA-83g2-8m93-v3w7 — golang.org/x/net: upgrade to the fixed version with the command below.

go get golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023

Details

Go through 1.15.12 and 1.16.x through 1.16.4 has a golang.org/x/net/html infinite loop via crafted ParseFragment input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/net
Introduced in: 0Fixed in: 0.0.0-20210520170846-37e1c6afe023
Fixgo get golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023

References