ZeroHour

CVE-2025-47911

CVSS 3.1
5.3 medium
EPSS
<1%p43
Published
()
Modified
Description

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Vendors
go
Products
html
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.