ZeroHour

CVE-2025-58190

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p41
Published
()
Modified
Description

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Vendors
go
Products
html
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.