Skip to main content

Vendor/product archive

golang / net CVEs

Beta · best-effort

12 CVEs tagged to golang / net1 Critical, 6 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-42506

Published May 22, 2026

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sani…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-42502

Published May 22, 2026

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sani…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-39821

Published May 22, 2026

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns t…

CVSS 9.6 · Critical
evidence mentions
91
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-27136

Published May 22, 2026

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sani…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-25681

Published May 22, 2026

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sani…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-25680

Published May 22, 2026

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2018-17848

Published Oct 1, 2018

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionMo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17847

Published Oct 1, 2018

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17846

Published Oct 1, 2018

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17143

Published Sep 17, 2018

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an ht…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17142

Published Sep 17, 2018

The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17075

Published Sep 16, 2018

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <templ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1