go

golang.org/x/net

View on go registry
50 Total advisories
50 Vulnerabilities
0 Malware

Dependency scanning

Check whether golang.org/x/net is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

UNKNOWN
Go

CVE-2026-25681

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-25680

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

MEDIUM 6.5
Go

CVE-2026-25680

Go Net HTML parser is vulnerable to denial of service

UNKNOWN
Go

CVE-2026-33814

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

UNKNOWN
Go

CVE-2026-42502

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-27136

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-42506

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

MEDIUM 5.3
SwiftURL KEV

CVE-2023-44487

HTTP/2 Stream Cancellation Attack

UNKNOWN
Go

CVE-2025-47911

Quadratic parsing complexity in golang.org/x/net/html

UNKNOWN
Go

CVE-2025-58190

Infinite parsing loop in golang.org/x/net

UNKNOWN
Go

CVE-2026-27141

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

MEDIUM 4.4
Go

CVE-2025-22870

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

UNKNOWN
Go

CVE-2025-22870

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

UNKNOWN
Go

CVE-2023-39325

HTTP/2 rapid reset can cause excessive work in net/http

UNKNOWN
Go

CVE-2024-45338

Non-linear parsing of case-insensitive content in golang.org/x/net/html

UNKNOWN
Go

CVE-2025-22872

golang.org/x/net vulnerable to Cross-site Scripting

UNKNOWN
Go

CVE-2025-22872

Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net

UNKNOWN
Go

CVE-2022-41717

Excessive memory growth in net/http and golang.org/x/net/http2

MEDIUM 5.3
Go

CVE-2022-41717

golang.org/x/net/http2 vulnerable to possible excessive memory growth

HIGH 7.5
Go

CVE-2023-39325

HTTP/2 rapid reset can cause excessive work in net/http

UNKNOWN
Go

CVE-2023-3978

Improper rendering of text nodes in golang.org/x/net/html

UNKNOWN
Go

CVE-2023-45288

HTTP/2 CONTINUATION flood in net/http

MEDIUM 5.9
Go

CVE-2021-31525

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

UNKNOWN
Go

CVE-2021-33194

Infinite loop when parsing inputs in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17847

Panic when parsing certain inputs in golang.org/x/net/html

MEDIUM 5.3
Go

CVE-2023-45288

net/http, x/net/http2: close connections when receiving too many headers

HIGH 7.5
Go

CVE-2018-17847

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

UNKNOWN
Go

CVE-2022-41723

Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net

HIGH 7.5
Go

CVE-2019-9512

golang.org/x/net/http vulnerable to a reset flood

HIGH 7.5
Go

CVE-2019-9512

golang.org/x/net/http vulnerable to ping floods

HIGH 7.5
Go

CVE-2021-33194

golang.org/x/net/html Infinite Loop vulnerability

UNKNOWN
Go

CVE-2021-31525

Panic due to large headers in net/http and golang.org/x/net/http/httpguts

HIGH 7.5
Go

CVE-2022-41723

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

UNKNOWN
Go

CVE-2022-27664

Denial of service in net/http and golang.org/x/net/http2

HIGH 7.5
Go

CVE-2022-41721

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

HIGH 7.5
Go

CVE-2018-17847

golang.org/x/net/html Improper Validation of Array Index vulnerability

HIGH 7.5
Go

CVE-2022-27664

golang.org/x/net/http2 Denial of Service vulnerability

UNKNOWN
Go

CVE-2022-41721

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

MEDIUM 6.1
Go

CVE-2023-3978

Improper rendering of text nodes in golang.org/x/net/html

UNKNOWN
Go

CVE-2019-9512

Reset flood in net/http and golang.org/x/net/http

HIGH 7.5
Go

CVE-2018-17143

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

HIGH 7.5
Go

CVE-2018-17142

golang.org/x/net/html NULL Pointer Dereference vulnerability

HIGH 7.5
Go

CVE-2018-17075

golang.org/x/net/html NULL Pointer Dereference vulnerability

HIGH 7.5
Go

CVE-2018-17846

x/net/html Vulnerable to DoS During HTML Parsing

UNKNOWN
Go

CVE-2021-44716

Unbounded memory growth in net/http and golang.org/x/net/http2

UNKNOWN
Go

CVE-2018-17143

Panic on unconsidered isindex and template combination in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17142

Incorrect parsing of nested templates in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17075

Panic when parsing malformed HTML in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17846

Infinite loop due to improper handling of "select" tags in golang.org/x/net/html

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes