---
id: CVE-2021-33194
title: 'golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)'
summary: >-
  A flaw was found in golang. An attacker can craft an input to ParseFragment
  within parse.go that would cause it to enter an infinite loop and never
  return. The greatest threat to the system is of availability.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-835
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - logging_subsystem_for_red_hat_openshift
  - openshift_service_mesh 2.0
  - ceph_storage 2
  - ceph_storage 3
  - enterprise_linux 7
  - openshift_container_platform 4
  - openshift_container_platform_assisted_installer 1
  - openshift_container_storage 4
  - openshift_logging 5.3
  - openshift_container_platform 4.8
  - openshift_container_platform 4.9
patched:
  - openshift_logging 5.3
  - openshift_container_platform 4.8
  - openshift_container_platform 4.9
published: '2021-05-20'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:22:15+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-33194'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1963232'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-33194'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-33194'
  - url: 'https://groups.google.com/g/golang-dev/c/28x0nthP-c8/m/KqWVTjsnBAAJ'
  - url: 'https://access.redhat.com/errata/RHSA-2021:4627'
  - url: 'https://access.redhat.com/errata/RHSA-2021:2438'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3759'
  - url: >-
      https://github.com/golang/net/commit/37e1c6afe02340126705deced573a85ab75209d7
  - url: 'https://go.dev/cl/311090'
  - url: 'https://go.dev/issue/46288'
  - url: 'https://go.googlesource.com/net/+/37e1c6afe02340126705deced573a85ab75209d7'
  - url: 'https://groups.google.com/g/golang-announce/c/wPunbCPkWUg'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4CHKSFMHZVOBCZSSVRE3UEYNKARTBMTM
  - url: 'https://pkg.go.dev/vuln/GO-2021-0238'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.07492
epssPercentile: 0.94265
aliases:
  - GHSA-83g2-8m93-v3w7
  - BIT-golang-2021-33194
  - GO-2021-0238
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.766Z'
---

## Overview

A flaw was found in golang. An attacker can craft an input to ParseFragment within parse.go that would cause it to enter an infinite loop and never return. The greatest threat to the system is of availability.

## Vendor advisories

- **RHSA-2021:4627** · Red Hat · fixed in: OpenShift Logging 5.3 · released 2021-11-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:4627)
- **RHSA-2021:2438** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.8 · released 2021-07-27 · [advisory](https://access.redhat.com/errata/RHSA-2021:2438)
- **RHSA-2021:3759** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.9 · released 2021-10-18 · [advisory](https://access.redhat.com/errata/RHSA-2021:3759)
- **Red Hat VEX** · Moderate · affected: Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 2.0, Red Hat Ceph Storage 2, Red Hat Ceph Storage 3, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ceph Storage 2, Red Hat Ceph Storage 3, Red Hat Enterprise Linux 7, Logging Subsystem for Red Hat OpenShift, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-33194.json)

**golang: x/net/html: infinite loop in ParseFragment** — rated Moderate by Red Hat. Released 2021-05-20, updated 2026-09-17.

Affected:

- Logging Subsystem for Red Hat OpenShift
- OpenShift Service Mesh 2.0
- Red Hat Ceph Storage 2
- Red Hat Ceph Storage 3
- Red Hat Enterprise Linux 7
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Container Platform Assisted Installer 1
- Red Hat Openshift Container Storage 4

Fixed:

- OpenShift Logging 5.3
- Red Hat OpenShift Container Platform 4.8
- Red Hat OpenShift Container Platform 4.9

No fix planned:

- Red Hat Ceph Storage 2
- Red Hat Ceph Storage 3
- Red Hat Enterprise Linux 7
- Logging Subsystem for Red Hat OpenShift
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Container Storage 4
- OpenShift Service Mesh 2.0
- Red Hat OpenShift Container Platform Assisted Installer 1

Not affected:

- OpenShift Logging 5.3
- Red Hat OpenShift Container Platform 4.8
- Red Hat OpenShift Container Platform 4.9
- OpenShift Serverless
- Red Hat Ceph Storage 4
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Container Storage 4

## Remediation

For OpenShift Container Platform 4.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html

For Red Hat OpenShift Logging 5.3, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html https://access.redhat.com/errata/RHSA-2021:4627
For OpenShift Container Platform 4.8 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html https://access.redhat.com/errata/RHSA-2021:2438
For OpenShift Container Platform 4.9 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.9/updating/updating-cluster-cli.html https://access.redhat.com/errata/RHSA-2021:3759

## Package advisory (CVE-2021-33194)

Affected packages:

- `golang.org/x/net < 0.0.0-20210520170846-37e1c6afe023`

Patched in:

- `golang.org/x/net 0.0.0-20210520170846-37e1c6afe023`

Source: https://osv.dev/vulnerability/GHSA-83g2-8m93-v3w7
