Golang-org-x-net
7 CVEs tracked since 2026. Since May 2026, none of them reached CISA KEV.
Golang-org-x-net CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-05 | 7 | 0 |
Products
The products that kept showing up in Golang-org-x-net's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Golang-org-x-net.
- CVE-2026-46600Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage7.5
- CVE-2026-27136Invoking duplicate attributes can cause XSS in golang.org/x/net/html6.1
- CVE-2026-42502Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html6.1
- CVE-2026-42506Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html6.1
- CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna9.6
- CVE-2026-25681Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html6.1
- CVE-2026-25680Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html6.5
- CVE-2026-33814Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net7.5
- CVE-2026-27141Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net7.5
- CVE-2025-58190Infinite parsing loop in golang.org/x/net5.3
- CVE-2025-47911Quadratic parsing complexity in golang.org/x/net/html5.3
- CVE-2025-22872Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net6.5
- CVE-2025-22870HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net4.4
- CVE-2024-45338Non-linear parsing of case-insensitive content in golang.org/x/net/html5.3
- CVE-2023-45288HTTP/2 CONTINUATION flood in net/http7.5
The record
- Peak rank
- #188 in May 2026
- Busiest month shown
- May 2026, 7 CVEs
- Months with a KEV entry
- 0 since May 2026
- Monthly snapshots
- 1 since 2026