Summary
It was discovered that Go Networking did not properly handle server errors after sending a GOAWAY frame during HTTP/2 connection shutdown, which could cause the connection to hang. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-27664)
It was discovered that Go Networking had quadratic complexity when decoding HPACK headers in HTTP/2 streams. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2022-41723)
It was discovered that Go Networking incorrectly rendered text nodes outside of the HTML namespace literally, causing text that should be escaped to not be escaped. A remote attacker could possibly use this issue to perform cross-site scripting attacks. (CVE-2023-3978)
Guido Vranken discovered that Go Networking processed certain inputs to the HTML parsing functions non-linearly with respect to their length. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2024-45338)
Sean Ng discovered that Go Networking incorrectly interpreted tags in foreign content with unquoted attribute values ending with a solidus character as self-closing, which could result in content being placed in the wrong scope during DOM construction. A remote attacker could possibly use this issue to perform cross-site scripting attacks. (CVE-2025-22872)
It was discovered that Go Networking had quadratic parsing complexity when processing certain HTML inputs. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2025-47911)
It was discovered that Go Networking could enter an infinite loop when parsing certain HTML inputs. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2025-58190)
It was discovered that Go Networking incorrectly accepted Punycode-encoded labels that decoded to ASCII-only labels when processing internationalized domain names. A remote attacker could possibly use this issue to bypass access control restrictions and escalate privileges. (CVE-2026-39821)
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
Separate remediation guidance was not included in the collected bulletin.
CVEs in this advisory 8
Updates
- Published by Ubuntu
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.