golang.org/x/[email protected] has vulnerabilities — update to latest
Update to >= 0.1.1-0.20221104162952-702349b0e862 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2018-17142 | golang.org/x/net/html NULL Pointer Dereference vulnerability | 0.0.0-20180925071336-cf3bd585ca2a |
| high | CVE-2019-9512 | golang.org/x/net/http vulnerable to a reset flood | 0.0.0-20190813141303-74dc4d7220e7 |
| high | CVE-2018-17847 | golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer | 0.0.0-20190125002852-4b62a64f59f7 |
| high | CVE-2018-17075 | golang.org/x/net/html NULL Pointer Dereference vulnerability | 0.0.0-20180816102801-aaf60122140d |
| high | BIT-golang-2022-27664 | golang.org/x/net/http2 Denial of Service vulnerability | 0.0.0-20220906165146-f3363e06e74c |
| high | BIT-golang-2021-33194 | golang.org/x/net/html Infinite Loop vulnerability | 0.0.0-20210520170846-37e1c6afe023 |
| high | CVE-2018-17143 | golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer | 0.0.0-20180921000356-2f5d2388922f |
| high | CVE-2022-41721 | golang.org/x/net/http2/h2c vulnerable to request smuggling attack | 0.1.1-0.20221104162952-702349b0e862 |
| medium | BIT-golang-2021-31525 | golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion | 0.0.0-20210428140749-89ef3d95e781 |
| high | CVE-2019-9512 | golang.org/x/net/http vulnerable to ping floods | 0.0.0-20190813141303-74dc4d7220e7 |
| high | CVE-2018-17847 | golang.org/x/net/html Improper Validation of Array Index vulnerability | 0.0.0-20190125002852-4b62a64f59f7 |
| medium | BIT-apisix-2023-44487 | HTTP/2 Stream Cancellation Attack | 10.5.3 |
| high | CVE-2018-17846 | x/net/html Vulnerable to DoS During HTML Parsing | 0.0.0-20190125091013-d26f9f9a57f3 |
| unknown | CVE-2018-17846 | Infinite loop due to improper handling of "select" tags in golang.org/x/net/html | 0.0.0-20190125091013-d26f9f9a57f3 |
| unknown | CVE-2018-17075 | Panic when parsing malformed HTML in golang.org/x/net/html | 0.0.0-20180816102801-aaf60122140d |
| unknown | BIT-golang-2021-33194 | Infinite loop when parsing inputs in golang.org/x/net/html | 0.0.0-20210520170846-37e1c6afe023 |
| unknown | CVE-2018-17142 | Incorrect parsing of nested templates in golang.org/x/net/html | 0.0.0-20180925071336-cf3bd585ca2a |
| unknown | CVE-2018-17143 | Panic on unconsidered isindex and template combination in golang.org/x/net/html | 0.0.0-20180921000356-2f5d2388922f |
| unknown | CVE-2018-17847 | Panic when parsing certain inputs in golang.org/x/net/html | 0.0.0-20190125002852-4b62a64f59f7 |
| unknown | BIT-golang-2021-31525 | Panic due to large headers in net/http and golang.org/x/net/http/httpguts | 0.0.0-20210428140749-89ef3d95e781 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/golang.org/x/netLast updated · 2026-04-09T19:17:33Z