golang.org/x/net/html Infinite Loop vulnerability
Overview
Source
ID
GHSA-83g2-8m93-v3w7
Aliases
BIT-golang-2021-33194
CVE-2021-33194
GO-2021-0238
Affected package
Description
Go through 1.15.12 and 1.16.x through 1.16.4 has a golang.org/x/net/html infinite loop via crafted ParseFragment input.
Impact
Severity
help_outline
Latest version of the CVSS score reported by the source of the advisory.
7.5 HIGH
Reference links
Summary
73.72k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
10.14k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
5.50%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20210520170846-37e1c6afe023
Patched/Unaffected
Affected