Non-linear parsing of case-insensitive content in golang.org/x/net/html
Overview
Source
ID
GO-2024-3333
Aliases
CVE-2024-45338
GHSA-w32m-9786-jp63
Affected package
Description
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
Summary
288.58k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
12.26k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
21.54%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.33.0
Patched/Unaffected
Affected