CVE-2026-25680
MediumAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,081
- of 17,828 indexed, latest versions
- Container images
- 3,735
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Net HTML parser is vulnerable to denial of service
Carried by container images the latest versions of 3,081 of 17,828 indexed charts deploy, on 3,735 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more | 0.55.0 | 3,735 |
- OSV records
- GHSA-5cv4-jp36-h3mw
- Also known as
- GO-2026-5028
Charts affected
3,081 by stars
Container images carrying it
3,735 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | 2e2b44393539 | golang.org/ | 0.55.0 | 3 |
| registry.k8s.io/ | 8ddd178ba5d0 | golang.org/ | 0.55.0 | 3 |
| registry.k8s.io/ | f1f352df9787 | golang.org/ | 0.55.0 | 3 |
| registry.k8s.io/ | c7e0a3718832 | golang.org/ | 0.55.0 | 3 |
| registry.k8s.io/ | 4dc0b87ccd69 | golang.org/ | 0.55.0 | 3 |
| registry.k8s.io/ | c825f3d5e28b | golang.org/ | 0.55.0 | 3 |
| 1password/ | 29d0c6cb67eb | golang.org/ | 0.55.0 | 2 |
| alazidis/ | 0e8c84152201 | golang.org/ | 0.55.0 | 2 |
| alpine/ | 048f8d9c8cc7 | golang.org/ | 0.55.0 | 2 |
| alpine/ | 9ccd82364762 | golang.org/ | 0.55.0 | 2 |
| alpine/ | ec8f734b0a10 | golang.org/ | 0.55.0 | 2 |
| altinity/ | cd9252644ce0 | golang.org/ | 0.55.0 | 2 |
| altinity/ | df3d57215356 | golang.org/ | 0.55.0 | 2 |
| amazon/ | b55277652ea8 | golang.org/ | 0.55.0 | 2 |
| amazon/ | c9b14856fd22 | golang.org/ | 0.55.0 | 2 |
| apache/ | afe59523a6c8 | golang.org/ | 0.55.0 | 2 |
| aquasec/ | ea3e33bc3c4e | golang.org/ | 0.55.0 | 2 |
| assistiot/ | ad8f72108636 | golang.org/ | 0.55.0 | 2 |
| ayushsobti/ | 4c94e8f8924e | golang.org/ | 0.55.0 | 2 |
| bitnamilegacy/ | 00176a47afa0 | golang.org/ | 0.55.0 | 2 |
| bitnamilegacy/ | d17df1f9d745 | golang.org/ | 0.55.0 | 2 |
| bitnamilegacy/ | a0a972324d93 | golang.org/ | 0.55.0 | 2 |
| bitnamisecure/ | 72ae5bd9715f | golang.org/ | 0.55.0 | 2 |
| bitpoke/ | f44fa86ab27e | golang.org/ | 0.55.0 | 2 |
| bitpoke/ | d86560c75bed | golang.org/ | 0.55.0 | 2 |
| bloomberg/ | a8ea8c61ff4c | golang.org/ | 0.55.0 | 2 |
| casbin/ | 7729da148c61 | golang.org/ | 0.55.0 | 2 |
| cesanta/ | 4d16885f3d4c | golang.org/ | 0.55.0 | 2 |
| cfssl/ | c9018c2ddf0b | golang.org/ | 0.55.0 | 2 |
| chankh/ | 963c44c7f8b1 | golang.org/ | 0.55.0 | 2 |
| coredns/ | 9b9128672209 | golang.org/ | 0.55.0 | 2 |
| crate/ | b8d89fa5d19b | golang.org/ | 0.55.0 | 2 |
| cs3org/ | 3b57a34a7dfd | golang.org/ | 0.55.0 | 2 |
| cs3org/ | e80a4d67b352 | golang.org/ | 0.55.0 | 2 |
| csiplugin/ | 0766163dc046 | golang.org/ | 0.55.0 | 2 |
| danielqsj/ | 4150e46b2e96 | golang.org/ | 0.55.0 | 2 |
| datawire/ | 1f67a1292d2a | golang.org/ | 0.55.0 | 2 |
| devopsfaith/ | f8bdaa8a1a43 | golang.org/ | 0.55.0 | 2 |
| dmilhdef/ | fada1a6e7638 | golang.org/ | 0.55.0 | 2 |
| drone/ | 4359bf2bb3dc | golang.org/ | 0.55.0 | 2 |
| filebrowser/ | 86e8449ff8ff | golang.org/ | 0.55.0 | 2 |
| filebrowser/ | c5d0a75a0041 | golang.org/ | 0.55.0 | 2 |
| fluxcd/ | 704d55295355 | golang.org/ | 0.55.0 | 2 |
| free5gc/ | 1bc96ff5a2a6 | golang.org/ | 0.55.0 | 2 |
| free5gc/ | 687ff4daf5da | golang.org/ | 0.55.0 | 2 |
| free5gc/ | e2a4dd98a4ed | golang.org/ | 0.55.0 | 2 |
| free5gc/ | 99e46b860efb | golang.org/ | 0.55.0 | 2 |
| free5gc/ | dfe8c68c04b4 | golang.org/ | 0.55.0 | 2 |
| free5gc/ | f712e8ecd927 | golang.org/ | 0.55.0 | 2 |
| free5gc/ | 60e38baa4b10 | golang.org/ | 0.55.0 | 2 |