UNKNOWN Go

Non-linear parsing of case-insensitive content in golang.org/x/net/html

GHSA-w32m-9786-jp63 · CVE-2024-45338 · GO-2024-3333

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

Ready to move

Start Securing

Free, no credit card | First findings in minutes