Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Go

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

GHSA-4r78-hx75-jjj2 · CVE-2018-17847 · CVE-2018-17848 · GHSA-mv93-wvcp-7m7r · GO-2022-0197

Published · Modified

Description

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a panic: runtime error (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

Ready to move

Start Securing

Free, no credit card | First findings in minutes