We found results for “”
CVE-2025-47911
Good to know:
Date: February 5, 2026
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Inefficient Algorithmic Complexity
CWE-407Top Fix
Upgrade Version
Upgrade to version github.com/golang/net - v0.45.0;golang.org/x/net - v0.45.0;https://github.com/golang/net.git - v0.45.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


