Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w4gw-w5jq-g9jh | golang.org/x/net/html has a Quadratic Parsing Complexity issue |
Ubuntu USN |
USN-8089-1 | Go Networking vulnerabilities |
Ubuntu USN |
USN-8089-2 | Go Networking vulnerabilities |
Ubuntu USN |
USN-8089-3 | ADSys, Juju Core, LXD vulnerabilities |
Wed, 18 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go
Go html |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:go:html:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Go
Go html |
Thu, 12 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang net |
|
| Vendors & Products |
Golang
Golang net |
Thu, 05 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | |
| Title | Quadratic parsing complexity in golang.org/x/net/html | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-02-12T15:23:55.509Z
Reserved: 2025-05-13T23:31:29.597Z
Link: CVE-2025-47911
Updated: 2026-02-12T15:23:50.510Z
Status : Analyzed
Published: 2026-02-05T18:16:09.893
Modified: 2026-02-18T17:48:49.760
Link: CVE-2025-47911
OpenCVE Enrichment
Updated: 2026-02-06T12:05:03Z
Github GHSA
Ubuntu USN