{"id":"USN-8900-1","summary":"golang-golang-x-net vulnerabilities","details":"It was discovered that Go Networking did not properly handle server\nerrors after sending a GOAWAY frame during HTTP/2 connection shutdown,\nwhich could cause the connection to hang. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2022-27664)\n\nIt was discovered that Go Networking had quadratic complexity when\ndecoding HPACK headers in HTTP/2 streams. A remote attacker could\npossibly use this issue to cause Go Networking to use excessive\nresources, leading to a denial of service. (CVE-2022-41723)\n\nIt was discovered that Go Networking incorrectly rendered text nodes\noutside of the HTML namespace literally, causing text that should be\nescaped to not be escaped. A remote attacker could possibly use this\nissue to perform cross-site scripting attacks. (CVE-2023-3978)\n\nGuido Vranken discovered that Go Networking processed certain inputs to\nthe HTML parsing functions non-linearly with respect to their length. A\nremote attacker could possibly use this issue to cause Go Networking to\nuse excessive resources, leading to a denial of service.\n(CVE-2024-45338)\n\nSean Ng discovered that Go Networking incorrectly interpreted tags in\nforeign content with unquoted attribute values ending with a solidus\ncharacter as self-closing, which could result in content being placed\nin the wrong scope during DOM construction. A remote attacker could\npossibly use this issue to perform cross-site scripting attacks.\n(CVE-2025-22872)\n\nIt was discovered that Go Networking had quadratic parsing complexity\nwhen processing certain HTML inputs. A remote attacker could possibly\nuse this issue to cause Go Networking to use excessive resources,\nleading to a denial of service. (CVE-2025-47911)\n\nIt was discovered that Go Networking could enter an infinite loop when\nparsing certain HTML inputs. A remote attacker could possibly use this\nissue to cause Go Networking to use excessive resources, leading to a\ndenial of service. (CVE-2025-58190)\n\nIt was discovered that Go Networking incorrectly accepted\nPunycode-encoded labels that decoded to ASCII-only labels when\nprocessing internationalized domain names. A remote attacker could\npossibly use this issue to bypass access control restrictions and\nescalate privileges. (CVE-2026-39821)","modified":"2026-10-08T12:58:04.913786145Z","published":"2026-10-07T19:09:10Z","related":["UBUNTU-CVE-2022-27664","UBUNTU-CVE-2022-41723","UBUNTU-CVE-2023-3978","UBUNTU-CVE-2024-45338","UBUNTU-CVE-2025-22872","UBUNTU-CVE-2025-47911","UBUNTU-CVE-2025-58190","UBUNTU-CVE-2026-39821"],"upstream":["CVE-2022-27664","CVE-2022-41723","CVE-2023-3978","CVE-2024-45338","CVE-2025-22872","CVE-2025-47911","CVE-2025-58190","CVE-2026-39821","UBUNTU-CVE-2022-27664","UBUNTU-CVE-2022-41723","UBUNTU-CVE-2023-3978","UBUNTU-CVE-2024-45338","UBUNTU-CVE-2025-22872","UBUNTU-CVE-2025-47911","UBUNTU-CVE-2025-58190","UBUNTU-CVE-2026-39821"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8900-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-27664"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-41723"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-3978"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-45338"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-22872"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-47911"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-58190"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-39821"}],"affected":[{"package":{"name":"golang-golang-x-net","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-golang-x-net?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1"}]}],"versions":["1:0.0+git20210119.5f4716e+dfsg-4","1:0.0+git20210805.aaa1db6+dfsg-1","1:0.0+git20211209.491a49a+dfsg-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1","binary_name":"golang-golang-x-net-dev"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"id":"CVE-2022-27664","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2022-41723","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-3978"},{"id":"CVE-2024-45338","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-22872"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-47911"},{"id":"CVE-2025-58190","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2026-39821"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8900-1.json"}}],"schema_version":"1.9.0"}