The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Html | Go | * | 0.45.0 (excluding) |
| Golang-golang-x-net | Ubuntu | devel | * |
| Golang-golang-x-net | Ubuntu | esm-apps/jammy | * |
| Golang-golang-x-net | Ubuntu | esm-apps/noble | * |
| Golang-golang-x-net | Ubuntu | jammy | * |
| Golang-golang-x-net | Ubuntu | noble | * |
| Golang-golang-x-net | Ubuntu | questing | * |
| Golang-golang-x-net | Ubuntu | upstream | * |