Panic when parsing certain inputs in golang.org/x/net/html
Overview
Source
ID
GO-2022-0197
Aliases
CVE-2018-17847
CVE-2018-17848
GHSA-4r78-hx75-jjj2
GHSA-mv93-wvcp-7m7r
Affected package
Description
The Parse function can panic on some invalid inputs.
For example, the Parse function panics on the input "<svg><template><desc><t><svg></template>".
Summary
6.13k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
1.51k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
0.46%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20190125002852-4b62a64f59f7
Patched/Unaffected
Affected