{"id":"CVE-2021-33194","title":"golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)","summary":"A flaw was found in golang. An attacker can craft an input to ParseFragment within parse.go that would cause it to enter an infinite loop and never return. The greatest threat to the system is of availability.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-835","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["logging_subsystem_for_red_hat_openshift","openshift_service_mesh 2.0","ceph_storage 2","ceph_storage 3","enterprise_linux 7","openshift_container_platform 4","openshift_container_platform_assisted_installer 1","openshift_container_storage 4","openshift_logging 5.3","openshift_container_platform 4.8","openshift_container_platform 4.9"],"patched":["openshift_logging 5.3","openshift_container_platform 4.8","openshift_container_platform 4.9"],"published":"2021-05-20","updated":"2026-09-17","sourceUpdated":"2026-09-17T18:22:15+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-33194"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1963232"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-33194"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33194"},{"url":"https://groups.google.com/g/golang-dev/c/28x0nthP-c8/m/KqWVTjsnBAAJ"},{"url":"https://access.redhat.com/errata/RHSA-2021:4627"},{"url":"https://access.redhat.com/errata/RHSA-2021:2438"},{"url":"https://access.redhat.com/errata/RHSA-2021:3759"},{"url":"https://github.com/golang/net/commit/37e1c6afe02340126705deced573a85ab75209d7"},{"url":"https://go.dev/cl/311090"},{"url":"https://go.dev/issue/46288"},{"url":"https://go.googlesource.com/net/+/37e1c6afe02340126705deced573a85ab75209d7"},{"url":"https://groups.google.com/g/golang-announce/c/wPunbCPkWUg"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4CHKSFMHZVOBCZSSVRE3UEYNKARTBMTM"},{"url":"https://pkg.go.dev/vuln/GO-2021-0238"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.07492,"epssPercentile":0.94206,"aliases":["GHSA-83g2-8m93-v3w7","BIT-golang-2021-33194","GO-2021-0238"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.766Z","slug":"CVE-2021-33194","body":"## Overview\n\nA flaw was found in golang. An attacker can craft an input to ParseFragment within parse.go that would cause it to enter an infinite loop and never return. The greatest threat to the system is of availability.\n\n## Vendor advisories\n\n- **RHSA-2021:4627** · Red Hat · fixed in: OpenShift Logging 5.3 · released 2021-11-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:4627)\n- **RHSA-2021:2438** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.8 · released 2021-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2021:2438)\n- **RHSA-2021:3759** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.9 · released 2021-10-18 · [advisory](https://access.redhat.com/errata/RHSA-2021:3759)\n- **Red Hat VEX** · Moderate · affected: Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 2.0, Red Hat Ceph Storage 2, Red Hat Ceph Storage 3, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ceph Storage 2, Red Hat Ceph Storage 3, Red Hat Enterprise Linux 7, Logging Subsystem for Red Hat OpenShift, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json)\n\n**golang: x/net/html: infinite loop in ParseFragment** — rated Moderate by Red Hat. Released 2021-05-20, updated 2026-09-17.\n\nAffected:\n\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Service Mesh 2.0\n- Red Hat Ceph Storage 2\n- Red Hat Ceph Storage 3\n- Red Hat Enterprise Linux 7\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Container Platform Assisted Installer 1\n- Red Hat Openshift Container Storage 4\n\nFixed:\n\n- OpenShift Logging 5.3\n- Red Hat OpenShift Container Platform 4.8\n- Red Hat OpenShift Container Platform 4.9\n\nNo fix planned:\n\n- Red Hat Ceph Storage 2\n- Red Hat Ceph Storage 3\n- Red Hat Enterprise Linux 7\n- Logging Subsystem for Red Hat OpenShift\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Container Storage 4\n- OpenShift Service Mesh 2.0\n- Red Hat OpenShift Container Platform Assisted Installer 1\n\nNot affected:\n\n- OpenShift Logging 5.3\n- Red Hat OpenShift Container Platform 4.8\n- Red Hat OpenShift Container Platform 4.9\n- OpenShift Serverless\n- Red Hat Ceph Storage 4\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Container Storage 4\n\n## Remediation\n\nFor OpenShift Container Platform 4.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html\n\nFor Red Hat OpenShift Logging 5.3, see the following instructions to apply this update:\n\nhttps://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html https://access.redhat.com/errata/RHSA-2021:4627\nFor OpenShift Container Platform 4.8 see the following documentation, which\nwill be updated shortly for this release, for important instructions on how\nto upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html\n\nDetails on how to access this content are available at\nhttps://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html https://access.redhat.com/errata/RHSA-2021:2438\nFor OpenShift Container Platform 4.9 see the following documentation, which\nwill be updated shortly for this release, for important instructions on how\nto upgrade your cluster and fully apply this asynchronous errata update:\n\nhttps://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html\n\nDetails on how to access this content are available at\nhttps://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html https://access.redhat.com/errata/RHSA-2021:3759\n\n## Package advisory (CVE-2021-33194)\n\nAffected packages:\n\n- `golang.org/x/net < 0.0.0-20210520170846-37e1c6afe023`\n\nPatched in:\n\n- `golang.org/x/net 0.0.0-20210520170846-37e1c6afe023`\n\nSource: https://osv.dev/vulnerability/GHSA-83g2-8m93-v3w7","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.5,"exploitation":0,"ransomware":0},"changes":[]}