Логотип exploitDog
bind:"CVE-2026-27142"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-27142"

Количество 9

Количество 9

ubuntu логотип

CVE-2026-27142

20 дней назад

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-27142

20 дней назад

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-27142

20 дней назад

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-27142

9 дней назад

URLs in meta content attribute actions are not escaped in html/template

EPSS: Низкий
debian логотип

CVE-2026-27142

20 дней назад

Actions which insert URLs into the content attribute of HTML meta tags ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-j4j7-vw47-rhfq

20 дней назад

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0875-1

15 дней назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20342-1

16 дней назад

Security update for go1.26

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0876-1

15 дней назад

Security update for go1.26

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27142

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 6.1
0%
Низкий
20 дней назад
redhat логотип
CVE-2026-27142

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 5.4
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-27142

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 6.1
0%
Низкий
20 дней назад
msrc логотип
CVE-2026-27142

URLs in meta content attribute actions are not escaped in html/template

0%
Низкий
9 дней назад
debian логотип
CVE-2026-27142

Actions which insert URLs into the content attribute of HTML meta tags ...

CVSS3: 6.1
0%
Низкий
20 дней назад
github логотип
GHSA-j4j7-vw47-rhfq

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

CVSS3: 7.5
0%
Низкий
20 дней назад
suse-cvrf логотип
SUSE-SU-2026:0875-1

Security update for go1.25

15 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20342-1

Security update for go1.26

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:0876-1

Security update for go1.26

15 дней назад

Уязвимостей на страницу