#1 Dependency Dashboard
openMaintained automatically by Cave. Dismiss false positives with cave deps dismiss.
11 open security alerts
Moderate (1)
- golang.org/x/net
v0.47.0(Go) — GHSA-5cv4-jp36-h3mw: Go Net HTML parser is vulnerable to denial of service — fix:0.55.0
Unknown (10)
- golang.org/x/net
v0.47.0(Go) — GO-2026-5942: Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage — fix:0.56.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5025: Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html — fix:0.55.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-4918: Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net — fix:0.53.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5026: Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna — fix:0.55.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5030: Invoking duplicate attributes can cause XSS in golang.org/x/net/html — fix:0.55.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5029: Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html — fix:0.55.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5028: Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html — fix:0.55.0 - golang.org/x/net
v0.47.0(Go) — GO-2026-5027: Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html — fix:0.55.0 - golang.org/x/sys
v0.38.0(Go) — GO-2026-5024: Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — fix:0.44.0 - golang.org/x/text
v0.31.0(Go) — GO-2026-5970: Infinite loop on invalid input in golang.org/x/text — fix:0.39.0
Comments (0)
No comments yet.