Dependency scanning
Check whether golang.org/x/net is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-39821
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-25681
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2026-25680
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVE-2026-25680
Go Net HTML parser is vulnerable to denial of service
CVE-2026-33814
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
CVE-2026-42502
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-27136
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-42506
Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
CVE-2023-44487
HTTP/2 Stream Cancellation Attack
CVE-2025-47911
Quadratic parsing complexity in golang.org/x/net/html
CVE-2025-58190
Infinite parsing loop in golang.org/x/net
CVE-2026-27141
Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net
CVE-2025-22870
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
CVE-2025-22870
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
CVE-2023-39325
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2024-45338
Non-linear parsing of case-insensitive content in golang.org/x/net/html
CVE-2025-22872
golang.org/x/net vulnerable to Cross-site Scripting
CVE-2025-22872
Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net
CVE-2022-41717
Excessive memory growth in net/http and golang.org/x/net/http2
CVE-2022-41717
golang.org/x/net/http2 vulnerable to possible excessive memory growth
CVE-2023-39325
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-3978
Improper rendering of text nodes in golang.org/x/net/html
CVE-2023-45288
HTTP/2 CONTINUATION flood in net/http
CVE-2021-31525
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
CVE-2021-33194
Infinite loop when parsing inputs in golang.org/x/net/html
CVE-2018-17847
Panic when parsing certain inputs in golang.org/x/net/html
CVE-2023-45288
net/http, x/net/http2: close connections when receiving too many headers
CVE-2018-17847
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2022-41723
Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
CVE-2019-9512
golang.org/x/net/http vulnerable to a reset flood
CVE-2019-9512
golang.org/x/net/http vulnerable to ping floods
CVE-2021-33194
golang.org/x/net/html Infinite Loop vulnerability
CVE-2021-31525
Panic due to large headers in net/http and golang.org/x/net/http/httpguts
CVE-2022-41723
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
CVE-2022-27664
Denial of service in net/http and golang.org/x/net/http2
CVE-2022-41721
golang.org/x/net/http2/h2c vulnerable to request smuggling attack
CVE-2018-17847
golang.org/x/net/html Improper Validation of Array Index vulnerability
CVE-2022-27664
golang.org/x/net/http2 Denial of Service vulnerability
CVE-2022-41721
Request smuggling due to improper request handling in golang.org/x/net/http2/h2c
CVE-2023-3978
Improper rendering of text nodes in golang.org/x/net/html
CVE-2019-9512
Reset flood in net/http and golang.org/x/net/http
CVE-2018-17143
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2018-17142
golang.org/x/net/html NULL Pointer Dereference vulnerability
CVE-2018-17075
golang.org/x/net/html NULL Pointer Dereference vulnerability
CVE-2018-17846
x/net/html Vulnerable to DoS During HTML Parsing
CVE-2021-44716
Unbounded memory growth in net/http and golang.org/x/net/http2
CVE-2018-17143
Panic on unconsidered isindex and template combination in golang.org/x/net/html
CVE-2018-17142
Incorrect parsing of nested templates in golang.org/x/net/html
CVE-2018-17075
Panic when parsing malformed HTML in golang.org/x/net/html
CVE-2018-17846
Infinite loop due to improper handling of "select" tags in golang.org/x/net/html
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes