HomeDefault status
unaffected
Any version before 0.45.0
affected
Description
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Problem types
CWE-400: Uncontrolled Resource Consumption
Product status
Any version before 0.45.0
Credits
Guido Vranken
Jakub Ciolek
References
github.com/golang/vulndb/issues/4440
groups.google.com/g/golang-announce/c/jnQcOYpiR2c