Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-27136 is a medium severity vulnerability in the golang.org/x/net/html package where parsing arbitrary HTML and rendering it using the Render function can produce an unexpected HTML tree. This behavior may be exploited to perform cross-site scripting (XSS) attacks in applications that rely on this package to sanitize input HTML before rendering. The vulnerability involves improper neutralization of input during web page generation (CWE-79). No official patch or remediation guidance is currently available from the vendor, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 05/22/2026, 15:01:22 UTC Added: 05/22/2026, 15:44:48 UTC |
CVE-2026-25681 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It arises when parsing arbitrary HTML and rendering it with the Render function, which can produce an unexpected HTML tree. This improper neutralization of input during web page generation may allow XSS attacks in applications relying on this package for HTML sanitization. No official patch or remediation guidance is currently available, and no known exploits exist in the wild. Join the discussion | CVE Database V5 | 05/22/2026, 15:01:21 UTC Added: 05/22/2026, 15:44:48 UTC |
0 CVE-2026-25680 is a vulnerability in the golang.org/x/net/html package where parsing arbitrary HTML can lead to excessive CPU consumption. This inefficient algorithmic complexity issue can cause denial of service by exhausting system resources. The vulnerability has a CVSS score of 6.5, indicating medium severity. There is no information about an available patch or official remediation at this time. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 05/22/2026, 15:01:21 UTC Added: 05/22/2026, 15:44:48 UTC |
CVE-2026-42502 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It arises when parsing arbitrary HTML and rendering it with the Render function, which can produce an unexpected HTML tree. This affects applications that sanitize input HTML before rendering, resulting in improper neutralization of input during web page generation. There is no official patch or remediation guidance available yet, and no known exploits have been reported in the wild. Join the discussion | CVE Database V5 | 05/22/2026, 15:01:21 UTC Added: 05/22/2026, 15:44:48 UTC |
CVE-2026-42506 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It occurs when parsing arbitrary HTML and rendering it using the Render function produces an unexpected HTML tree. This improper neutralization of input during web page generation can allow XSS attacks in applications relying on this package for HTML sanitization. No official patch or remediation guidance is currently available. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/22/2026, 15:01:21 UTC Added: 05/22/2026, 15:44:48 UTC |
0 The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. Join the discussion | CVE Database V5 | 02/05/2026, 17:48:44 UTC Added: 02/05/2026, 18:00:09 UTC |
0 The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. Join the discussion | CVE Database V5 | 02/05/2026, 17:48:44 UTC Added: 02/05/2026, 18:00:09 UTC |
Showing 1 to 7 of 7 results