CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go Standard Library
Go Standard Library html/template |
|
| Vendors & Products |
Go Standard Library
Go Standard Library html/template |
Thu, 07 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 07 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS. | |
| Title | Bypass of meta content URL escaping causes XSS in html/template | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-05-07T19:41:19.524Z
Reserved: 2026-04-07T18:13:03.527Z
Link: CVE-2026-39823
No data.
Status : Awaiting Analysis
Published: 2026-05-07T20:16:43.290
Modified: 2026-05-07T20:38:04.860
Link: CVE-2026-39823
No data.
OpenCVE Enrichment
Updated: 2026-05-07T23:00:07Z
Weaknesses