VDB
DEBIAN-CVE-2025-58190
DEBIAN-CVE-2025-58190
PUBLISHED
CVSS 5.300000190734863 MEDIUM
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | golang-golang-x-net | 1:0.19.0+dfsg-1, 1:0.10.0-1, 1:0.11.0-1 |
| Debian:13 | golang-golang-x-net | 1:0.27.0-2, 1:0.53.0-2, 0 |
| Debian:14 | golang-golang-x-net | 0.27.0-2, 0, 1:0.27.0-2 |
| Debian:12 | golang-golang-x-net | 0.24.0+dfsg, 0.25.0+dfsg, 0.26.0+dfsg |
Timeline
- Feb 5, 2026 CVE Published
- Apr 28, 2026 CVE Updated