CVE-2025-47911

MEDIUM5.3EPSS 0.02%

Quadratic parsing complexity in golang.org/x/net/html

發布日:2026/2/12修改日:2026/5/15

描述

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

參考連結(7)