The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 07 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 06 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang net |
|
| Vendors & Products |
Golang
Golang net |
Thu, 05 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | |
| Title | Infinite parsing loop in golang.org/x/net | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-02-05T17:48:44.693Z
Reserved: 2025-08-27T14:50:58.692Z
Link: CVE-2025-58190
No data.
Status : Awaiting Analysis
Published: 2026-02-05T18:16:10.027
Modified: 2026-02-05T20:47:37.777
Link: CVE-2025-58190
OpenCVE Enrichment
Updated: 2026-02-06T12:05:07Z
Weaknesses