Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-6019

Опубликовано: 29 апр. 2026
Источник: msrc
EPSS Низкий

Описание

BaseCookie.js_output() does not neutralize embedded characters

EPSS

Процентиль: 14%
0.00229
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.8
redhat
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
nvd
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
debian
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and ...

CVSS3: 6.1
github
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

EPSS

Процентиль: 14%
0.00229
Низкий