HomeDefault status
unaffected
Any version before 1.25.10
affected
1.26.0-0 (semver) before 1.26.3
affected
Description
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 1.25.10
1.26.0-0 (semver) before 1.26.3
Credits
Samy Ghannad
References
groups.google.com/g/golang-announce/c/qcCIEXso47M