Description

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

INFO

Published Date :

2026-02-05T17:48:44.693Z

Last Modified :

2026-02-12T15:22:37.685Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2025-58190 vulnerability.

Vendors Products
Go
  • Html
Golang
  • Net

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact