CVE-2025-47911

Published: February 10, 2026Last modified: February 25, 2026

Description

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbuildahNot affected (1.39.8-r0)
containerdNot affected (1.7.30-r0)
dockerUnknown (20.10.24-r17)
podmanUnknown (5.6.2-r4)
runcNot affected (1.1.4-r3)
skopeoNot affected (1.10.0-r2)
25 LTSbuildahNot affected (1.41.8-r0)
containerdNot affected (2.1.6-r0)
dockerUnknown (28.2.1-r0)
podmanUnknown (5.6.2-r4)
runcNot affected (1.3.0-r1)
skopeoNot affected (1.20.0-r5)
StreambuildahNot affected (1.42.0-r0)
containerdNot affected (2.2.1-r0)
dockerNot affected (29.0.2-r0)
podmanNot affected (5.7.0-r0)
runcNot affected (1.1.7-r1)
skopeoNot affected (1.20.0-r6)

References

ON THIS PAGE