CVE-2026-25680
MediumAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,099
- of 17,821 indexed, latest versions
- Container images
- 3,758
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Net HTML parser is vulnerable to denial of service
Carried by container images the latest versions of 3,099 of 17,821 indexed charts deploy, on 3,758 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more | 0.55.0 | 3,758 |
- OSV records
- GHSA-5cv4-jp36-h3mw
- Also known as
- GO-2026-5028
Charts affected
3,099 by stars
Container images carrying it
3,758 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | c81f105c3682 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 1808ffb76f37 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 316c397906c9 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 372d991e5888 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 56690a89c79a | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 9a5a3eb4a213 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a1bc133af84e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 067e54e2e107 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c966a4f8a4b7 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0c4b6132b0ad | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0312232b31a2 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | b7da7c554018 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | e161eddc59a0 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7d8c669f11a4 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 1b099cfe9e5e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a752b6aee537 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 9e24d8a6a3b2 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 74426c1fe00f | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 74c1bee92e04 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7439f6f9f85c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 45ca15fc294f | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | d22095ee8a1a | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 08265c006973 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0e05a7b49c33 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 6d4106724d56 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 8abb52b66557 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 10006bc0f309 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | aca1bbd609b6 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c66cc93f9d03 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 3cceb9462ae1 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4b22b4f407c4 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 43401e216e89 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4f6da0256b1b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | b18964551d8e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | b3a87f92a963 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4d763d58f11d | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 9977511cb142 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 39412bdd403b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 97febecbe6cb | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c4b1d3d0f052 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 94c9a3e799c2 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0d6d0df98fe4 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 175512bb3f61 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 82d0adcce816 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 229b05e3c717 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 3c20900b5381 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 6bebbda31416 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 9751856cacc8 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | e72aa733faf2 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ec4e5dfe12b6 | golang.org/ | 0.55.0 | 1 |