Vulnerability GO-2026-4341
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 months ago
January 28, 2026 at 07:08 PM UTC
Memory exhaustion in query parameter parsing in net/url
<1.24.12
<1.24.12
Summary
Memory exhaustion in query parameter parsing in net/url
Details
The net/url package does not set a limit on the number of query parameters in a query.
While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
1 month ago
Enforce maximum recursion depth in encoding/asn1
<1.25.13 GO-2026-5972
<1.25.13 GO-2026-5972
Unknown
1 month ago
Add recursion depth guard during decode in encoding/xml
<1.25.13 GO-2026-6088
<1.25.13 GO-2026-6088
Unknown
1 month ago
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
<1.25.13 GO-2026-6089
<1.25.13 GO-2026-6089
Unknown
1 month ago
Limit handshake messages we are willing to accept post-handshake in crypto/tls
<1.25.13 GO-2026-6090
<1.25.13 GO-2026-6090
Unknown
1 month ago
Fix Javascript regexp context tracking in html/template
<1.25.13 GO-2026-6091
<1.25.13 GO-2026-6091
Impacted packages
Timeline
Published
8 months ago
January 28, 2026 at 07:08 PM UTC
Last Modified
2 hours ago
October 03, 2026 at 10:41 AM UTC