Lucene search

K
osvGoogleOSV:GHSA-4R78-HX75-JJJ2
HistoryMay 13, 2022 - 1:19 a.m.

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

2022-05-1301:19:29
Google
osv.dev
24

0.004 Low

EPSS

Percentile

74.2%

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a panic: runtime error (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.