CVE-2025-58190
MEDIUMgo/html < 0.45.0 - Denial of Service via Infinite Parsing Loop
Title source: llmDescription
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
References (4)
Core 4
Core References
Various Sources
https://go.dev/cl/709875
Various Sources
https://pkg.go.dev/vuln/GO-2026-4441
Issue Tracking
https://github.com/golang/vulndb/issues/4441
Scores
CVSS v3
5.3
EPSS
0.0048
EPSS Percentile
37.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (1)
go/html
< 0.45.0
Published
Feb 05, 2026
Tracked Since
Feb 18, 2026