Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56858

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

A flaw was found in the html/template component of Go (golang). Pathological inputs could prematurely close an unescaped forward slash ('/'), allowing an attacker to inject arbitrary content. This could lead to Cross-Site Scripting (XSS), where malicious scripts are executed in a user's browser, potentially compromising user data or actions.

Отчет

This is an Important cross-site scripting (XSS) vulnerability in the Go html/template package. Applications utilizing this package to render untrusted input are susceptible to arbitrary content injection due to a flaw in how pathological inputs are handled, potentially leading to client-side script execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
AWS Load Balancer Operatoralbo/aws-load-balancer-controller-rhel8Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-operator-bundleAffected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Cryostat 4cryostat/cryostat-storage-rhel9Not affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2515838html/template: golang: Go html/template: Cross-Site Scripting via pathological input

EPSS

Процентиль: 23%
0.0031
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
23 дня назад

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

CVSS3: 6.1
nvd
23 дня назад

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

msrc
16 дней назад

Fix Javascript regexp context tracking in html/template

CVSS3: 6.1
debian
23 дня назад

Previously, pathological inputs could close an unescaped '/' early, al ...

CVSS3: 6.1
github
23 дня назад

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

EPSS

Процентиль: 23%
0.0031
Низкий

8.1 High

CVSS3