<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Dependency-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/dependency-security/</link><description>Recent content in Dependency-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 08:43:47 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/dependency-security/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-25680: Go HTML Parser DoS Vulnerability</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-25680-golang-x-net-html-denial-of-service-azure/</link><pubDate>Thu, 04 Jun 2026 08:43:47 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-25680-golang-x-net-html-denial-of-service-azure/</guid><description>CVE-2026-25680 allows denial of service via malicious HTML in golang.org/x/net/html. Azure-hosted Go apps processing untrusted HTML should patch immediatel</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25680">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-25680 is a denial-of-service vulnerability in the golang.org/x/net/html package, which is widely used by Go applications to parse HTML. An attacker can trigger the flaw by supplying specially crafted HTML input, causing the parser to consume excessive resources and crash or become unresponsive. Any Azure-hosted or Azure-integrated Go application that processes untrusted HTML content may be at risk.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your Go-based workloads and container images for dependencies on golang.org/x/net and update to the patched version immediately; pay particular attention to internet-facing services that accept user-supplied or third-party HTML input, as these are the most directly exposed.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25680">CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html</a></p>
]]></content:encoded></item></channel></rss>