| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-42506 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Parsing arbitrary HTML which is then rendered using Render can result ... |
| CVE-2026-42502 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Parsing arbitrary HTML which is then rendered using Render can result ... |
| CVE-2026-39821 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ... |
| CVE-2026-33814 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | When processing HTTP/2 SETTINGS frames, transport will enter an infini ... |
| CVE-2026-27136 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Parsing arbitrary HTML which is then rendered using Render can result ... |
| CVE-2026-25681 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Parsing arbitrary HTML which is then rendered using Render can result ... |
| CVE-2026-25680 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Parsing arbitrary HTML can consume excessive CPU time, possibly leadin ... |
| CVE-2025-58190 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | The html.Parse function in golang.org/x/net/html has an infinite parsi ... |
| CVE-2025-47911 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | The html.Parse function in golang.org/x/net/html has quadratic parsing ... |
| CVE-2025-22872 | vulnerable (no DSA) | fixed | fixed | fixed | The tokenizer incorrectly interprets tags with unquoted attribute valu ... |
| CVE-2024-45338 | vulnerable (no DSA) | fixed | fixed | fixed | An attacker can craft an input to the Parse functions that would be pr ... |
| CVE-2023-45288 | vulnerable (no DSA) | fixed | fixed | fixed | An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of ... |
| CVE-2023-3978 | vulnerable (no DSA) | fixed | fixed | fixed | Text nodes not in the HTML namespace are incorrectly literally rendere ... |
| Bug | Description |
|---|
| CVE-2026-46600 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... |
| CVE-2026-27141 | Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a ... |
| CVE-2022-41723 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumpt ... |
| CVE-2022-41721 | A request smuggling attack is possible when using MaxBytesHandler. Whe ... |
| CVE-2022-41717 | An attacker can cause excessive memory growth in a Go server accepting ... |
| CVE-2022-27664 | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ... |
| CVE-2021-44716 | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontro ... |
| CVE-2021-33194 | golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows atta ... |
| CVE-2021-31525 | net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote a ... |