UBUNTU-CVE-2021-33194
High
UBUNTU-CVE-2021-33194
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
Exploit probability
Not scored
Published
May 26, 2021
Required by
Not available
Last source change
April 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
21 explicit affected versions
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
UBUNTU-CVE-2021-33194
View original source
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
05 / REFERENCES
Further evidence
- https://groups.google.com/g/golang-announce/c/wPunbCPkWUg
- https://groups.google.com/g/golang-dev/c/28x0nthP-c8/m/KqWVTjsnBAAJ
- https://ubuntu.com/security/CVE-2021-33194
- https://ubuntu.com/security/notices/USN-8089-2
- https://ubuntu.com/security/notices/USN-8089-3
- https://www.cve.org/CVERecord?id=CVE-2021-33194