Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:golang/golang.org/x/net/html

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-27136 is a medium severity vulnerability in the golang.org/x/net/html package where parsing arbitrary HTML and rendering it using the Render function can produce an unexpected HTML tree. This behavior may be exploited to perform cross-site scripting (XSS) attacks in applications that rely on this package to sanitize input HTML before rendering. The vulnerability involves improper neutralization of input during web page generation (CWE-79). No official patch or remediation guidance is currently available from the vendor, and no known exploits are reported in the wild.

Join the discussion

CVE-2026-25681 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It arises when parsing arbitrary HTML and rendering it with the Render function, which can produce an unexpected HTML tree. This improper neutralization of input during web page generation may allow XSS attacks in applications relying on this package for HTML sanitization. No official patch or remediation guidance is currently available, and no known exploits exist in the wild.

Join the discussion

CVE-2026-25680 is a vulnerability in the golang.org/x/net/html package where parsing arbitrary HTML can lead to excessive CPU consumption. This inefficient algorithmic complexity issue can cause denial of service by exhausting system resources. The vulnerability has a CVSS score of 6.5, indicating medium severity. There is no information about an available patch or official remediation at this time. No known exploits are reported in the wild.

Join the discussion

CVE-2026-42502 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It arises when parsing arbitrary HTML and rendering it with the Render function, which can produce an unexpected HTML tree. This affects applications that sanitize input HTML before rendering, resulting in improper neutralization of input during web page generation. There is no official patch or remediation guidance available yet, and no known exploits have been reported in the wild.

Join the discussion

CVE-2026-42506 is a medium severity cross-site scripting (XSS) vulnerability in the golang.org/x/net/html package. It occurs when parsing arbitrary HTML and rendering it using the Render function produces an unexpected HTML tree. This improper neutralization of input during web page generation can allow XSS attacks in applications relying on this package for HTML sanitization. No official patch or remediation guidance is currently available. There are no known exploits in the wild at this time.

Join the discussion

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Join the discussion

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:golang/golang.org/x/net/html
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses