Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39823

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a tag's attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the attribute, the escaper would fail to similarly escape it, leading to XSS.

A flaw was found in the html/template package of Go. A remote attacker could exploit this vulnerability by inserting ASCII whitespaces around the equals sign (=) within a URL's content attribute inside a <meta> tag. This improper escaping could lead to Cross-Site Scripting (XSS), allowing the attacker to execute malicious scripts in the user's browser.

Отчет

Red Hat products ship the Go html/template package as a dependency of various Go-based components. The affected functionality involves URL escaping inside <meta> tag content attributes, which requires an application to render user-controlled URLs in meta tags using html/template. While the vulnerable code is present, exploitation requires a specific usage pattern that is uncommon in Red Hat product code paths.

Меры по смягчению последствий

Ensure that user-supplied URLs are validated and sanitized before being passed to Go's html/template package for rendering in HTML meta tag content attributes. Avoid rendering untrusted URL data directly in meta tag content attributes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Compliance Operatorcompliance/openshift-compliance-operator-bundleFix deferred
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2467811html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content

EPSS

Процентиль: 24%
0.00314
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

CVSS3: 6.1
nvd
3 месяца назад

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

msrc
3 месяца назад

Bypass of meta content URL escaping causes XSS in html/template

CVSS3: 6.1
debian
3 месяца назад

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...

CVSS3: 6.1
github
3 месяца назад

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

EPSS

Процентиль: 24%
0.00314
Низкий

5.4 Medium

CVSS3