Vulnerability Report: GO-2026-4982

standard library

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

Affected Packages

Aliases

References

Credits

  • Samy Ghannad

Feedback

See anything missing or incorrect? Suggest an edit to this report.