Launch Week Day 1: Announcing Security Design Review
go

golang.org/x/net

View on go registry
49 Total advisories
49 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
Go

CVE-2026-39821

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

UNKNOWN
Go

CVE-2026-25680

Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-42502

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-27136

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-42506

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

UNKNOWN
Go

CVE-2026-25681

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

MEDIUM 5.3
SwiftURL KEV

CVE-2023-44487

HTTP/2 Stream Cancellation Attack

UNKNOWN
Go

CVE-2025-47911

Quadratic parsing complexity in golang.org/x/net/html

UNKNOWN
Go

CVE-2025-58190

Infinite parsing loop in golang.org/x/net

UNKNOWN
Go

CVE-2026-27141

Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

UNKNOWN
Go

CVE-2026-33814

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

MEDIUM 4.4
Go

CVE-2025-22870

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

UNKNOWN
Go

CVE-2025-22870

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

UNKNOWN
Go

CVE-2023-39325

HTTP/2 rapid reset can cause excessive work in net/http

UNKNOWN
Go

CVE-2024-45338

Non-linear parsing of case-insensitive content in golang.org/x/net/html

UNKNOWN
Go

CVE-2025-22872

golang.org/x/net vulnerable to Cross-site Scripting

UNKNOWN
Go

CVE-2025-22872

Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net

UNKNOWN
Go

CVE-2022-41717

Excessive memory growth in net/http and golang.org/x/net/http2

MEDIUM 5.3
Go

CVE-2022-41717

golang.org/x/net/http2 vulnerable to possible excessive memory growth

HIGH 7.5
Go

CVE-2023-39325

HTTP/2 rapid reset can cause excessive work in net/http

UNKNOWN
Go

CVE-2023-3978

Improper rendering of text nodes in golang.org/x/net/html

UNKNOWN
Go

CVE-2023-45288

HTTP/2 CONTINUATION flood in net/http

MEDIUM 5.9
Go

CVE-2021-31525

golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion

UNKNOWN
Go

CVE-2021-33194

Infinite loop when parsing inputs in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17847

Panic when parsing certain inputs in golang.org/x/net/html

MEDIUM 5.3
Go

CVE-2023-45288

net/http, x/net/http2: close connections when receiving too many headers

HIGH 7.5
Go

CVE-2018-17847

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

UNKNOWN
Go

CVE-2022-41723

Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net

HIGH 7.5
Go

CVE-2019-9512

golang.org/x/net/http vulnerable to a reset flood

HIGH 7.5
Go

CVE-2019-9512

golang.org/x/net/http vulnerable to ping floods

HIGH 7.5
Go

CVE-2021-33194

golang.org/x/net/html Infinite Loop vulnerability

UNKNOWN
Go

CVE-2021-31525

Panic due to large headers in net/http and golang.org/x/net/http/httpguts

HIGH 7.5
Go

CVE-2022-41723

golang.org/x/net vulnerable to Uncontrolled Resource Consumption

UNKNOWN
Go

CVE-2022-27664

Denial of service in net/http and golang.org/x/net/http2

HIGH 7.5
Go

CVE-2022-41721

golang.org/x/net/http2/h2c vulnerable to request smuggling attack

HIGH 7.5
Go

CVE-2018-17847

golang.org/x/net/html Improper Validation of Array Index vulnerability

HIGH 7.5
Go

CVE-2022-27664

golang.org/x/net/http2 Denial of Service vulnerability

UNKNOWN
Go

CVE-2022-41721

Request smuggling due to improper request handling in golang.org/x/net/http2/h2c

MEDIUM 6.1
Go

CVE-2023-3978

Improper rendering of text nodes in golang.org/x/net/html

UNKNOWN
Go

CVE-2019-9512

Reset flood in net/http and golang.org/x/net/http

HIGH 7.5
Go

CVE-2018-17143

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

HIGH 7.5
Go

CVE-2018-17142

golang.org/x/net/html NULL Pointer Dereference vulnerability

HIGH 7.5
Go

CVE-2018-17075

golang.org/x/net/html NULL Pointer Dereference vulnerability

HIGH 7.5
Go

CVE-2018-17846

x/net/html Vulnerable to DoS During HTML Parsing

UNKNOWN
Go

CVE-2021-44716

Unbounded memory growth in net/http and golang.org/x/net/http2

UNKNOWN
Go

CVE-2018-17143

Panic on unconsidered isindex and template combination in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17142

Incorrect parsing of nested templates in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17075

Panic when parsing malformed HTML in golang.org/x/net/html

UNKNOWN
Go

CVE-2018-17846

Infinite loop due to improper handling of "select" tags in golang.org/x/net/html

Ready to move

Start Securing

Free, no credit card | First findings in minutes