Lucene search

K
osvGoogleOSV:GHSA-5P4H-3377-7W67
HistoryMay 13, 2022 - 1:19 a.m.

golang.org/x/net/html NULL Pointer Dereference vulnerability

2022-05-1301:19:22
Google
osv.dev
9
golang webkit software vulnerability runtime error frameset html package htmltreebuilder.cpp noreferrer 2018-07-13 go mishandles panic objects applet marquee .

EPSS

0.004

Percentile

72.6%

The html package (aka x/net/html) before 2018-07-13 in Go mishandles “in frameset” insertion mode, leading to a “panic: runtime error” for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.