CVE-2025-58190: Infinite parsing loop in golang.org/x/net
Published Feb 5, 2026
·Updated
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Affected Software
3 affected components
golang.org/x/net/html
go Html Go<0.45.0
IBM API Connect V12 OnPrem<=All
Remediation
Patch Available
Event History
Feb 5, 2026
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58190?
CVE-2025-58190 has a severity rating that allows it to cause denial of service (DoS) through infinite parsing loops.
2
How do I fix CVE-2025-58190?
To fix CVE-2025-58190, update your golang.org/x/net/html package to the latest version that addresses the vulnerability.
3
What type of vulnerability is CVE-2025-58190?
CVE-2025-58190 is a denial of service vulnerability caused by an infinite parsing loop.
4
Who is affected by CVE-2025-58190?
Any software utilizing the golang.org/x/net/html package to parse HTML content is affected by CVE-2025-58190.
5
What systems are vulnerable to CVE-2025-58190?
Systems that rely on the golang.org/x/net/html for HTML parsing are vulnerable to CVE-2025-58190.