The HTML parser does not properly handle "in frameset" insertion mode, and can be made to panic when operating on malformed HTML that contains tags. If operating on user input, this may be a vector for a denial of service attack.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2021-0078"
}