CVE-2025-58190

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2026
Last modified:
18/02/2026

Description

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:go:html:*:*:*:*:*:go:*:* 0.45.0 (excluding)