| CVE-2026-27141 |
unknown |
— |
— |
|
|
|
3mo ago |
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic |
| CVE-2025-47911 |
unknown |
— |
— |
|
|
|
4mo ago |
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted H… |
| CVE-2025-58190 |
unknown |
— |
— |
|
|
|
4mo ago |
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML … |
| CVE-2025-22872 |
unknown |
— |
— |
|
|
|
1y ago |
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly… |
| CVE-2024-45338 |
unknown |
— |
— |
|
|
|
2y ago |
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service. |
| CVE-2022-41721 |
unknown |
— |
— |
|
|
|
3y ago |
A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from th… |
| CVE-2021-33194 |
unknown |
— |
— |
|
|
|
4y ago |
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input. |