blob: 2a1cdcedc59fbaaabfa7066003fc5d7197438550 [file] [log] [blame]
modules:
- module: golang.org/x/net
versions:
- fixed: 0.0.0-20210520170846-37e1c6afe023
packages:
- package: golang.org/x/net/html
symbols:
- inHeadIM
description: |
An attacker can craft an input to ParseFragment that causes it
to enter an infinite loop and never return.
published: 2022-02-17T17:33:43Z
cves:
- CVE-2021-33194
credit: discovered by OSS-Fuzz and reported by Andrew Thornton
references:
- fix: https://go.dev/cl/311090
- fix: https://go.googlesource.com/net/+/37e1c6afe02340126705deced573a85ab75209d7
- report: https://go.dev/issue/46288
- web: https://groups.google.com/g/golang-announce/c/wPunbCPkWUg