CVE-2026-25680
Moderate
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Exploit probability
0.3%
Published
May 22, 2026
Required by
Not available
Last source change
July 1, 2026
02 / AFFECTED SOFTWARE
Affected packages
54 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2026-5028
View original source
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Open Source Vulnerabilities
GHSA-5cv4-jp36-h3mw
View original source
In Go Net (`golang.org/x/net`) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
Open Source Vulnerabilities
CVE-2026-25680
View original source
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
05 / REFERENCES
Further evidence
- https://go.dev/cl/781702
- https://go.dev/issue/79573
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- cs.opensource.google/go/x/net
- https://go.googlesource.com/net/+/08be507abce89191d78cd49da60f4501fc910472
- https://go.googlesource.com/net/+/refs/tags/v0.55.0
- https://nvd.nist.gov/vuln/detail/CVE-2026-25680
- https://pkg.go.dev/vuln/GO-2026-5028
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25680.json
- https://pkg.go.dev