CVE-2025-58190

MEDIUM5.3EPSS 0.01%

Infinite parsing loop in golang.org/x/net

發布日:2026/2/5修改日:2026/5/15

描述

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

參考連結(4)