CVE-2026-39823

Published: May 13, 2026Last modified: May 16, 2026

Description

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

Severity score breakdown

ParameterValue
Base score6.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.10-r0)
25 LTSgoFixed (1.25.10-r0)
StreamgoFixed (1.26.3-r0)
Hardened Containers23 LTSgoFixed (1.25.10-r0)
25 LTSgoFixed (1.25.10-r0)
StreamgoFixed (1.26.3-r0)

References

ON THIS PAGE