The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Html | Go | * | 0.45.0 (excluding) |
| Multicluster engine for Kubernetes 2.9 | RedHat | multicluster-engine/hive-rhel9:sha256:0b03429102eea10cc0733872bbc946bbfa378966b5d62e32762bd7a59c23e9de | * |