VendorsGolangnetany version
Vulnerabilities

Golang Net any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Published 2026-05-22 · Modified
9.6EPSS 0.006
CVE-2018-17075
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.
Published 2018-09-16 · Modified
7.5EPSS 0.028
CVE-2018-17143
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.
Published 2018-09-17 · Modified
7.5EPSS 0.028
CVE-2018-17846
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.
Published 2018-10-01 · Modified
7.5EPSS 0.026
CVE-2018-17142
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.
Published 2018-09-17 · Modified
7.5EPSS 0.024
CVE-2018-17847
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.
Published 2018-10-01 · Modified
7.5EPSS 0.024
CVE-2018-17848
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.
Published 2018-10-01 · Modified
7.5EPSS 0.022
CVE-2026-25680
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
Published 2026-05-22 · Analyzed
6.5EPSS 0.005
CVE-2026-42506
Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
Published 2026-05-22 · Analyzed
6.1EPSS 0.003
CVE-2026-25681
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Published 2026-05-22 · Analyzed
6.1EPSS 0.002
CVE-2026-27136
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Published 2026-05-22 · Analyzed
6.1EPSS 0.002
CVE-2026-42502
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Published 2026-05-22 · Analyzed
6.1EPSS 0.002