CVE-2026-25681
בינונית 6.1
תיאור (מקור, אנגלית)
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/10/2026
- CWE
- CWE-1021
מוצרים מושפעים
golang: net
קישורים
- https://pkg.go.dev/vuln/GO-2026-5029 Vendor Advisory
- https://go.dev/cl/781703 Issue Tracking
- https://go.dev/issue/79574 Issue Tracking
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 Mailing List