Package impact

golang Go / golang.org/x/net

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-39821 critical 9.6 9.6 7d ago The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…
CVE-2026-25680 medium 6.5 6.5 7d ago Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVE-2026-42506 medium 6.1 6.1 7d ago Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
CVE-2026-42502 medium 6.1 6.1 7d ago Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
CVE-2026-27136 medium 6.1 6.1 7d ago Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
CVE-2026-25681 medium 6.1 6.1 7d ago Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
CVE-2023-3978 medium 5.5 3y ago Moderate: podman security, bug fix, and enhancement update
CVE-2022-41723 medium 5.5 3y ago Moderate: toolbox security and bug fix update
CVE-2022-27664 medium 5.5 3y ago Moderate: git-lfs security and bug fix update
CVE-2022-41717 medium 5.5 3y ago Moderate: git-lfs security and bug fix update
CVE-2021-31525 medium 5.5 4y ago RHSA-2021:3076: go-toolset:rhel8 security, bug fix, and enhancement update (Moderate)