CVE-2024-45338: Golang.org/x/net Golang.org/x/net/html
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
Affected products
- Golang.org/x/net Golang.org/x/net/html: before 0.33.0 (fixed in 0.33.0)
Published 2024-12-18. Last modified 2026-06-17.