CVE-2026-25680
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
| Vendor | golang.org/x/net |
| Product | golang.org/x/net/html |
| Published | May 22, 2026 |
| Last Updated | May 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/net golang.org/x/net/html
Be the first to know when new medium vulnerabilities affecting golang.org/x/net golang.org/x/net/html are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/net / golang.org/x/net/html
0 < 0.55.0
References
Credits
IPC Labs