Back to Database
Status published
Unknown
CVE-2023-3978
Improper rendering of text nodes in golang.org/x/net/html
Vulnerability Description
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3978
Credits & Attribution
No credits recorded in the NVD database.
More from golang.org/x/net
View All →CVE-2025-58190
Infinite parsing loop in golang.org/x/net
Unknown
0
CVE-2025-47911
Quadratic parsing complexity in golang.org/x/net/html
Unknown
0
CVE-2025-22872
Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net
Unknown
0
CVE-2024-45338
Non-linear parsing of case-insensitive content in golang.org/x/net/html
Unknown
0
CVE-2022-41721
Request smuggling due to improper request handling in golang.org/x/net/http2/h2c
Unknown
0
Affected Vendor
golang.org/x/net
View all reports →Affected Software
golang.org/x/net/html
Vulnerable Versions:
0
Timeline
Official Publish:
August 2nd, 2023
Last Modified:
September 27th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.