Search CVE reports


Toggle filters

11 – 16 of 16 results


CVE-2025-47911

Medium priority

Some fixes available 8 of 10

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, adsys, containerd, golang-golang-x-net-dev, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Vulnerable Fixed Fixed — —
adsys Not affected Not affected Not affected Not affected —
containerd Not affected Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 7 packages Show less packages

CVE-2025-22872

Medium priority

Some fixes available 8 of 14

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing,...

7 affected packages

golang-golang-x-net, containerd, adsys, golang-golang-x-net-dev, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Fixed Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
adsys Not affected Not affected Not affected Not affected —
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core — — — — —
lxd — — — Not affected Fixed
Show all 7 packages Show less packages

CVE-2024-45338

Medium priority

Some fixes available 13 of 17

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

7 affected packages

golang-golang-x-net, adsys, containerd, golang-golang-x-net-dev, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Vulnerable Fixed Fixed Not in release —
adsys Fixed Fixed Fixed Fixed —
containerd Not affected Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core Not in release Not in release Not in release Not in release —
lxd Not in release Not in release Not in release Not affected Not affected
Show all 7 packages Show less packages

CVE-2023-3978

Medium priority

Some fixes available 8 of 12

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

7 affected packages

golang-golang-x-net, containerd, golang-golang-x-net-dev, adsys, google-guest-agent...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
adsys Not affected Not affected Not affected Fixed —
google-guest-agent Not affected Not affected Not affected Not affected Not affected
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 7 packages Show less packages

CVE-2022-41723

Medium priority

Some fixes available 23 of 39

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.

20 affected packages

golang-golang-x-net, containerd, golang-1.13, adsys, golang...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
containerd Not affected Not affected Not affected Not affected Not affected
golang-1.13 Not in release Not in release Vulnerable Vulnerable Vulnerable
adsys Not affected Not affected Not affected Fixed —
golang Not in release Not in release Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Not in release Vulnerable
golang-1.14 Not in release Not in release Not in release Vulnerable Not in release
golang-1.16 Not in release Not in release Not in release Vulnerable Vulnerable
golang-1.17 Not in release Not in release Fixed Not in release Not in release
golang-1.18 Not in release Not in release Fixed Fixed Fixed
golang-1.19 Not in release Not in release Not in release Not in release Not in release
golang-1.20 Not in release Not in release Not affected Not affected Not in release
golang-1.21 Not in release Not affected Not affected Not affected Not in release
golang-1.6 Not in release Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Not in release Vulnerable
golang-1.9 Not in release Not in release Not in release Not in release Vulnerable
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
google-guest-agent Fixed Fixed Fixed Fixed Fixed
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 20 packages Show less packages

CVE-2022-27664

Medium priority

Some fixes available 26 of 39

In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

17 affected packages

golang-1.13, golang-1.14, golang-1.16, golang-1.17, golang-1.18...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-1.13 Not in release Not in release Fixed Fixed Fixed
golang-1.14 — — Not in release Vulnerable Not in release
golang-1.16 — — Not in release Fixed Fixed
golang-1.17 — — Vulnerable Not in release Not in release
golang-1.18 Not in release Not in release Fixed Fixed Fixed
golang-1.8 — — Not in release Not in release Vulnerable
golang-1.9 — — Not in release Not in release Vulnerable
golang-golang-x-net Not affected Not affected Fixed Not in release Not in release
google-guest-agent Fixed Fixed Fixed Fixed Needs evaluation
containerd Not affected Not affected Not affected Not affected Not affected
adsys Not affected Not affected Not affected Fixed —
golang — — Not in release Not in release Not in release
golang-1.10 — — Not in release Not in release Vulnerable
golang-1.6 — — Not in release Not in release Not in release
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
juju-core Not in release Not in release Not in release — —
lxd Not in release Not in release Not in release Not affected Fixed
Show all 17 packages Show less packages