The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | |
| Title | Quadratic parsing complexity in golang.org/x/net/html | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-02-05T17:48:44.562Z
Reserved: 2025-05-13T23:31:29.597Z
Link: CVE-2025-47911
No data.
Status : Received
Published: 2026-02-05T18:16:09.893
Modified: 2026-02-05T18:16:09.893
Link: CVE-2025-47911
No data.
OpenCVE Enrichment
No data.