CVE-2026-56858

Published: August 15, 2026Last modified: August 26, 2026

Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Severity score breakdown

ParameterValue
Base score6.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.14-r0)
25 LTSgoFixed (1.25.14-r0)
StreamgoFixed (1.26.7-r0)
Hardened Containers23 LTSgoFixed (1.25.14-r0)
25 LTSgoFixed (1.25.14-r0)
StreamgoFixed (1.26.7-r0)

References

ON THIS PAGE