Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42502

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

A flaw was found in golang.org/x/net/html. This vulnerability allows an attacker to manipulate how HTML is processed and displayed. By providing specially crafted HTML, an attacker can cause an unexpected structure in the rendered output. This can lead to Cross-Site Scripting (XSS) attacks, where malicious scripts are executed in a user's web browser, potentially compromising user data or taking control of their session.

Отчет

A flaw in golang.org/x/net/html can lead to Cross-Site Scripting (XSS) in applications that parse and render untrusted HTML, even with sanitization attempts. This is due to an unexpected HTML tree structure, allowing malicious scripts to execute in a user's browser.

Меры по смягчению последствий

Applications utilizing golang.org/x/net/html should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-rhel9-operatorAffected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2480762golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering

EPSS

Процентиль: 13%
0.00223
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
nvd
3 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
msrc
2 месяца назад

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

CVSS3: 6.1
debian
3 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result ...

CVSS3: 6.1
github
2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

EPSS

Процентиль: 13%
0.00223
Низкий

6.1 Medium

CVSS3