HIGH 7.5 Go

golang.org/x/net/html Infinite Loop vulnerability

GHSA-83g2-8m93-v3w7 · BIT-golang-2021-33194 · CVE-2021-33194 · GO-2021-0238

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Go through 1.15.12 and 1.16.x through 1.16.4 has a golang.org/x/net/html infinite loop via crafted ParseFragment input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes