The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Html | Go | * | 0.45.0 (excluding) |
| Red Hat Hardened Images | RedHat | golang1-26-main-1.26.2-1.hum1 | * |
| Red Hat Hardened Images | RedHat | golang1-25-main-1.25.9-1.hum1 | * |
| Golang-golang-x-net | Ubuntu | devel | * |
| Golang-golang-x-net | Ubuntu | esm-apps/jammy | * |
| Golang-golang-x-net | Ubuntu | esm-apps/noble | * |
| Golang-golang-x-net | Ubuntu | esm-apps/resolute | * |
| Golang-golang-x-net | Ubuntu | jammy | * |
| Golang-golang-x-net | Ubuntu | noble | * |
| Golang-golang-x-net | Ubuntu | questing | * |
| Golang-golang-x-net | Ubuntu | resolute | * |
| Golang-golang-x-net | Ubuntu | upstream | * |
| Golang-golang-x-net-dev | Ubuntu | esm-apps/bionic | * |
| Golang-golang-x-net-dev | Ubuntu | esm-apps/focal | * |
| Golang-golang-x-net-dev | Ubuntu | esm-infra-legacy/xenial | * |
| Golang-golang-x-net-dev | Ubuntu | esm-infra/xenial | * |
| Juju-core | Ubuntu | esm-infra-legacy/xenial | * |
| Juju-core | Ubuntu | esm-infra/xenial | * |
| Lxd | Ubuntu | esm-infra-legacy/xenial | * |
| Lxd | Ubuntu | esm-infra/bionic | * |
| Lxd | Ubuntu | esm-infra/xenial | * |