CVE-2026-25680
MediumAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,099
- of 17,821 indexed, latest versions
- Container images
- 3,758
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Net HTML parser is vulnerable to denial of service
Carried by container images the latest versions of 3,099 of 17,821 indexed charts deploy, on 3,758 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more | 0.55.0 | 3,758 |
- OSV records
- GHSA-5cv4-jp36-h3mw
- Also known as
- GO-2026-5028
Charts affected
3,099 by stars
Container images carrying it
3,758 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | ebcf66281fc1 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | f9063e20b1f6 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 5c9e99ff7167 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7cde8c3fa2d1 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 6a8546993cb5 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 020edbaee890 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 274a179fd402 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 62eaa9c9a929 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 00cd9316a379 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | cfe98ae544df | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | b803fbe1cdb8 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 03c1ddbda33b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 24a0113d5fb0 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | de42151adff6 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 324f9b7b689c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | cdba39e3f3d0 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | da81246ccfc9 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 5f7b4c6dd299 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 34c5a1e351d6 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c8ac95a30c31 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 72e7e77f8091 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 58f4f180aa6e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | e897b18db13d | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 3620d5680775 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 032e977d9adf | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 20f066d0f631 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7db1a1bf3dae | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 09c782ca5984 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 46a71d75dfd3 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ed120caf710c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ca01f5ab95f7 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 6f031172a5ec | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 04f4c4bb7cdd | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7ed73c1979ee | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 2088dcb22aaa | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 2ce23f948e02 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ae85d68749c7 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0af2faec9d6f | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | d45fc24e8f43 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c7adcc4db378 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 2627be646391 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0c58ff972451 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 015f5ba04bcb | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 07d51f838f0d | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4709f1bb3039 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | e6e0fbd7cca9 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4e1a3ef1fe82 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 71d1f1c0179e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 878ef6a31fa0 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c298183a5208 | golang.org/ | 0.55.0 | 1 |