{"id":"CVE-2024-45338","aliases":["GHSA-w32m-9786-jp63","GO-2024-3333"],"url":"https://o3.security/vulnerability/CVE-2024-45338","summary":"Non-linear parsing of case-insensitive content in golang.org/x/net/html","details":"An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.","published":"2024-12-18T21:15:08Z","modified":"2026-08-27T17:40:57.932434724Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"golang.org/x/net/html","fixedVersion":"0.33.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250221-0001/"},{"type":"WEB","url":"https://go.dev/cl/637536"},{"type":"WEB","url":"https://go.dev/issue/70906"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-3333"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T17:40:57.932434724Z"}}