CVE-2025-22872 - CVE House
Back to Database
Status published Unknown CVE-2025-22872

Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net

Vulnerability Description

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-22872

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sean Ng (https://ensy.zip)

Affected Vendor

golang.org/x/net

View all reports →

Affected Software

golang.org/x/net/html
Vulnerable Versions:
0

Timeline

Official Publish: April 16th, 2025
Last Modified: May 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.