{"schema_version":"1.7.5","id":"CVE-2025-47911","published":"2026-02-05T18:16:09.893Z","modified":"2026-08-27T17:40:57.740072887Z","aliases":["GHSA-w4gw-w5jq-g9jh","GO-2026-4440"],"related":["CGA-mhf2-24x8-jgh8","SUSE-SU-2025:21043-1","SUSE-SU-2025:21221-1","SUSE-SU-2025:4190-1","SUSE-SU-2025:4444-1","SUSE-SU-2025:4446-1","SUSE-SU-2025:4479-1","SUSE-SU-2025:4482-1","SUSE-SU-2026:0028-1","SUSE-SU-2026:0403-1","SUSE-SU-2026:0580-1","SUSE-SU-2026:20089-1","SUSE-SU-2026:20176-1","SUSE-SU-2026:20244-1","SUSE-SU-2026:20357-1","SUSE-SU-2026:20685-1","SUSE-SU-2026:2096-1","SUSE-SU-2026:22242-1","SUSE-SU-2026:22249-1","SUSE-SU-2026:22558-1","SUSE-SU-2026:2400-1","SUSE-SU-2026:2401-1","SUSE-SU-2026:2493-1","SUSE-SU-2026:3056-1","SUSE-SU-2026:3630-1","openSUSE-SU-2025:15607-1","openSUSE-SU-2025:15616-1","openSUSE-SU-2025:15617-1","openSUSE-SU-2025:15618-1","openSUSE-SU-2025:15619-1","openSUSE-SU-2025:15620-1","openSUSE-SU-2025:15624-1","openSUSE-SU-2025:15647-1","openSUSE-SU-2025:15654-1","openSUSE-SU-2025:15669-1","openSUSE-SU-2025:15689-1","openSUSE-SU-2025:15709-1","openSUSE-SU-2025:15722-1","openSUSE-SU-2025:15729-1","openSUSE-SU-2025:15730-1","openSUSE-SU-2025:15743-1","openSUSE-SU-2025:15779-1","openSUSE-SU-2025:15830-1","openSUSE-SU-2025:15852-1","openSUSE-SU-2025:15854-1","openSUSE-SU-2025:20118-1","openSUSE-SU-2025:20128-1","openSUSE-SU-2025:20143-1","openSUSE-SU-2025:20160-1","openSUSE-SU-2026:10173-1","openSUSE-SU-2026:10862-1","openSUSE-SU-2026:11126-1","openSUSE-SU-2026:11294-1","openSUSE-SU-2026:11514-1","openSUSE-SU-2026:11520-1","openSUSE-SU-2026:20044-1","openSUSE-SU-2026:20058-1","openSUSE-SU-2026:20105-1","openSUSE-SU-2026:20132-1","openSUSE-SU-2026:20206-1","openSUSE-SU-2026:20318-1","openSUSE-SU-2026:20327-1","openSUSE-SU-2026:20654-1","openSUSE-SU-2026:20730-1","openSUSE-SU-2026:20798-1","openSUSE-SU-2026:20892-1","openSUSE-SU-2026:21210-1","openSUSE-SU-2026:21367-1","openSUSE-SU-2026:21483-1","openSUSE-SU-2026:21603-1","openSUSE-SU-2026:21662-1"],"details":"The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47911.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"0.45.0"}]}]}}],"references":[{"type":"ADVISORY","url":"https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2026-4440"},{"type":"REPORT","url":"https://github.com/golang/vulndb/issues/4440"},{"type":"FIX","url":"https://go.dev/cl/709876"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}