5
CVSSv2

CVE-2021-33194

Published: 26/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows malicious users to cause a denial of service (infinite loop) via crafted ParseFragment input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

fedoraproject fedora 36

Vendor Advisories

No description is available for this CVE ...
Version v000-20210520170846-37e1c6afe023 of golangorg/x/net fixes a vulnerability in the golangorg/x/net/html package which could cause a denial of service An attacker can craft an input to ParseFragment that would cause it to enter an infinite loop and never return ...