golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-33194.json"