github.com/golang/net is vulnerable to denial of service. A panic: runtime error
occurs in inBodyIM
in parse.go
when the html.Parse
is called with an unclosed tag, resulting in a denial of service condition.
github.com/golang/go/issues/27702
github.com/golang/go/issues/27704
go-review.googlesource.com/c/net/+/136575
lists.fedoraproject.org/archives/list/[email protected]/message/LREEWY6KNLHRWFZ7OT4HVLMVVCGGUHON/
lists.fedoraproject.org/archives/list/[email protected]/message/UKRCI7WIOCOCD3H7NXWRGIRABTQOZOBK/