Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39826

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

If a trusted template author were to write a

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Compliance Operatorcompliance/openshift-compliance-operator-bundleFix deferred
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2467826html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping

EPSS

Процентиль: 29%
0.00371
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

CVSS3: 6.1
nvd
3 месяца назад

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

msrc
3 месяца назад

Escaper bypass leads to XSS in html/template

CVSS3: 6.1
debian
3 месяца назад

If a trusted template author were to write a <script> tag containing a ...

CVSS3: 6.1
github
3 месяца назад

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

EPSS

Процентиль: 29%
0.00371
Низкий

5.4 Medium

CVSS3