golang.org/x/net vulnerabilities
CVEs whose affected-version data names the golang.org/x/net package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-25680Medium· 6.5Go Net HTML parser is vulnerable to denial of service
Go Net HTML parser is vulnerable to denial of service
CVE-2026-42502Medium· 6.1Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-27136NoneInvoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-25681NoneInvoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2023-45288Medium· 5.3PoCnet/http, x/net/http2: close connections when receiving too many headers
net/http, x/net/http2: close connections when receiving too many headers
CVE-2023-39325High· 7.5PoCHTTP/2 rapid reset can cause excessive work in net/http
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-3978Medium· 6.1Improper rendering of text nodes in golang.org/x/net/html
Improper rendering of text nodes in golang.org/x/net/html
CVE-2022-27664High· 7.5golang.org/x/net/http2 Denial of Service vulnerability
golang.org/x/net/http2 Denial of Service vulnerability
CVE-2018-17847High· 7.5golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer