CVE Vulnerabilities

CVE-2025-58190

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Feb 05, 2026 | Modified: Feb 18, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
HtmlGo*0.45.0 (excluding)
Multicluster engine for Kubernetes 2.9RedHatmulticluster-engine/hive-rhel9:sha256:0b03429102eea10cc0733872bbc946bbfa378966b5d62e32762bd7a59c23e9de*

References