CVE-2025-22872Patch

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-10: 103-10
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Minimus@minimusio
    Patch

    CVEs are inevitable. Slow remediation doesn’t have to be. In this post, we show how Minimus detected a Go vulnerability (CVE-2025-22872), updated the vulnerable module, rebuilt the package, and published a new image, all in under 12 hours: https://buff.ly/idywglH A real example of how Minimus keeps MTTR (Mean Time to Resolution) low through continuous vulnerability detection, source-built components, and automated rebuilds!

    Post summary

    The post showcases Minimus repairing CVE-2025-22872 by updating the vulnerable Go module, rebuilding the package, and releasing a new image within 12 hours, underscoring rapid patching and low MTTR.

    00010103
    51 followersView on X

Explore more