CVE-2026-42506

NameCVE-2026-42506
DescriptionParsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-golang-x-net-devsource(unstable)(unfixed)

Notes

https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
https://github.com/golang/go/issues/79571

Search for package or bug name: Reporting problems