6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Description
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Basic Information
ID
CVE-2026-25680
Source
Go
Published
May 22, 2026 at 15:01
Modified
May 22, 2026 at 17:00
Affected Product
Vendor
golang.org/x/net
Product
golang.org/x/net/html
Affected Versions
golang.org/x/net golang.org/x/net/html 0