Количество 9
Количество 9
CVE-2026-27142
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
CVE-2026-27142
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
CVE-2026-27142
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
CVE-2026-27142
URLs in meta content attribute actions are not escaped in html/template
CVE-2026-27142
Actions which insert URLs into the content attribute of HTML meta tags ...
GHSA-j4j7-vw47-rhfq
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
SUSE-SU-2026:0875-1
Security update for go1.25
openSUSE-SU-2026:20342-1
Security update for go1.26
SUSE-SU-2026:0876-1
Security update for go1.26
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-27142 Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0. | CVSS3: 6.1 | 0% Низкий | 20 дней назад | |
CVE-2026-27142 Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0. | CVSS3: 5.4 | 0% Низкий | 20 дней назад | |
CVE-2026-27142 Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0. | CVSS3: 6.1 | 0% Низкий | 20 дней назад | |
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template | 0% Низкий | 9 дней назад | ||
CVE-2026-27142 Actions which insert URLs into the content attribute of HTML meta tags ... | CVSS3: 6.1 | 0% Низкий | 20 дней назад | |
GHSA-j4j7-vw47-rhfq Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0. | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
SUSE-SU-2026:0875-1 Security update for go1.25 | 15 дней назад | |||
openSUSE-SU-2026:20342-1 Security update for go1.26 | 16 дней назад | |||
SUSE-SU-2026:0876-1 Security update for go1.26 | 15 дней назад |
Уязвимостей на страницу