CVE-2026-42506
בינונית 6.1
תיאור (מקור, אנגלית)
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/10/2026
- CWE
- CWE-79
מוצרים מושפעים
golang: net
קישורים
- https://pkg.go.dev/vuln/GO-2026-5025 Vendor Advisory
- https://go.dev/cl/781700 Issue Tracking
- https://go.dev/issue/79571 Issue Tracking
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 Mailing List