The following vulnerability was published for golang-golang-x-net.
CVE-2025-22872[0]:
| The tokenizer incorrectly interprets tags with unquoted attribute
| values that end with a solidus character (/) as self-closing. When
| directly using Tokenizer, this can result in such tags incorrectly
| being marked as self-closing, and when using the Parse functions,
| this can result in content following such tags as being placed in
| the wrong scope during DOM construction, but only when tags are in
| foreign content (e.g. <math>, <svg>, etc contexts).
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.