CVE-2026-25680
MediumAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,099
- of 17,821 indexed, latest versions
- Container images
- 3,758
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Net HTML parser is vulnerable to denial of service
Carried by container images the latest versions of 3,099 of 17,821 indexed charts deploy, on 3,758 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more | 0.55.0 | 3,758 |
- OSV records
- GHSA-5cv4-jp36-h3mw
- Also known as
- GO-2026-5028
Charts affected
3,099 by stars
Container images carrying it
3,758 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 2a2bb32c0ea8 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | f279fd7dc112 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 29458113b8b6 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 57419b6d3830 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 50b431281d3e | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c8882543f693 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 83276357d448 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 86ab878da25a | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | d22616a5998b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 02348a19aeae | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 112fc427d933 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 72dc058e478d | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a87c42275757 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | c8227c6edb4d | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 167fd532bd43 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 73a2ebae4413 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | f312f50ddc57 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a6f2155bd822 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 8fdd311a6d33 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 487bfc37c4b4 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | acf22310e9dd | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0f7d277bb2b2 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | b40439329191 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ebd03028ff6a | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 96d600ae97b4 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 4e77eff2d906 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 58bed8d1e7fc | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | f22cae0e6cf3 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 27a5c64b7ea8 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a7fce69e171c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 3475404bef5c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 3acba3df8827 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 365183f83ac9 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | fc256885915b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 6de40f528be9 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 0cbced8e6240 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 455f6e7a26fd | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 47f88b18fb7c | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | f52e66eff50b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 791c8f9d885a | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 5d5e24119ff1 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | a7e922ddac55 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 8de556d3bda7 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | df6b11907d33 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 7bfe1c07bd9b | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | ec36422b09af | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 42574f512837 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 9518de37eed5 | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | e24894e32cbc | golang.org/ | 0.55.0 | 1 |
| ghcr.io/ | 49b1c312e342 | golang.org/ | 0.55.0 | 1 |