Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-50674

CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

XMLWordPrintable

    • Critical
    • None
    • False
    • Hide

      None

      Show
      None
    • Release Note Not Required
    • In Progress
    • False

      Security Tracking Issue

      Do not make this issue public.

      Flaw:


      Non-linear parsing of case-insensitive content in golang.org/x/net/html
      https://bugzilla.redhat.com/show_bug.cgi?id=2333122

      An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

              jeffbnowicki Jeff Nowicki
              amshriva01 Aman Shrivastava
              Zhaohua Sun Zhaohua Sun
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: