Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5160

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.

A flaw was found in github.com/yuin/goldmark/renderer/html. This Cross-site Scripting (XSS) vulnerability allows a remote attacker to execute arbitrary scripts in the context of applications that render a malicious URL. The flaw stems from an improper ordering of URL validation and normalization, where the component validates link destinations before resolving HTML entities. This enables an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references, leading to unauthorized code execution.

Отчет

This vulnerability is rated as Moderate as user interaction is required by accessing the maliciously crafted content in order to an attacker perform the exploit. A Cross-site Scripting (XSS) flaw exists in github.com/yuin/goldmark/renderer/html due to incorrect ordering of URL validation and HTML entity resolution. This allows an attacker to bypass protocol filtering by encoding dangerous schemes, leading to arbitrary script execution when a malicious URL is rendered.

Меры по смягчению последствий

To mitigate this vulnerability, avoid rendering untrusted content with applications utilizing github.com/yuin/goldmark/renderer/html. Ensure that all input processed by the affected component is thoroughly sanitized to prevent the injection of malicious HTML entities or dangerous URL schemes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2458616github.com/yuin/goldmark/renderer/html: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation

EPSS

Процентиль: 21%
0.00287
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.

CVSS3: 6.1
nvd
4 месяца назад

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.

CVSS3: 6.1
msrc
4 месяца назад

Описание отсутствует

CVSS3: 6.1
debian
4 месяца назад

Versions of the package github.com/yuin/goldmark/renderer/html before ...

CVSS3: 6.1
github
4 месяца назад

goldmark vulnerable to Cross-site Scripting (XSS)

EPSS

Процентиль: 21%
0.00287
Низкий

6.1 Medium

CVSS3