VDB
KO

GO-2026-5028

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

Details

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / golang.org/x/net
Introduced in: 0 Fixed in: 0.55.0
Fix go get golang.org/x/net@v0.55.0

References