VYPR
High severity7.5NVD Advisory· Published Oct 1, 2018· Updated Jun 17, 2026

CVE-2018-17846

CVE-2018-17846

Description

The html package (aka x/net/html) through 2018-09-25 in Go mishandles , leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
golang.org/x/netGo
< 0.0.0-20190125091013-d26f9f9a57f30.0.0-20190125091013-d26f9f9a57f3

Affected products

4
  • ghsa-coords
    Range: < 0.0.0-20190125091013-d26f9f9a57f3
  • cpe:2.3:a:golang:net:*:*:*:*:*:*:*:*
    Range: <=2018-09-25
  • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.