> USN-8900-1: Go Networking vulnerabilities
[DATE: 07/10/2026 19:09]
[LANGUAGE: EN]
It was discovered that Go Networking did not properly handle server
errors after sending a GOAWAY frame during HTTP/2 connection shutdown,
which could cause the connection to hang. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2022-27664)
It was discovered that Go Networking had quadratic complexity when
decoding HPACK headers in HTTP/2 streams. A remote attacker could
possibly use this issue to cause Go Networking to use excessive
resources, leading to a denial of service. (CVE-2022-41723)
It was discovered that Go Networking incorrectly rendered text nodes
outside of the HTML namespace literally, causing text that should be
escaped to not be escaped. A remote attacker could possibly use this
issue to perform cross-site scripting attacks. (CVE-2023-3978)
Guido Vranken discovered that Go Networking processed certain inputs to
the HTML parsing functions non-linearly with respect to their length. A
remote attacker could possibly use this issue to cause Go Networking to
use excessive resources, leading to a denial of service.
(CVE-2024-45338)
Sean Ng discovered that Go Networking incorrectly interpreted tags in
foreign content with unquoted attribute values ending with a solidus
character as self-closing, which could result in content being placed
in the wrong scope during DOM construction. A remote attacker could
possibly use this issue to perform cross-site scripting attacks.
(CVE-2025-22872)
It was discovered that Go Networking had quadratic parsing complexity
when processing certain HTML inputs. A remote attacker could possibly
use this issue to cause Go Networking to use excessive resources,
leading to a denial of service. (CVE-2025-47911)
It was discovered that Go Networking could enter an infinite loop when
parsing certain HTML inputs. A remote attacker could possibly use this
issue to cause Go Networking to use excessive resources, leading to a
denial of service. (CVE-2025-58190)
It was discovered that Go Networking incorrectly accepted
Punycode-encoded labels that decoded to ASCII-only labels when
processing internationalized domain names. A remote attacker could
possibly use this issue to bypass access control restrictions and
escalate privileges. (CVE-2026-39821)