FlawAtlas
Search the atlas
CVE-2023-3978 Moderate

Improper rendering of text nodes in golang.org/x/net/html

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

Exploit probability 0.9%
Published August 2, 2023
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

12 explicit affected versions

Go golang.org/x/net
Go golang.org/x/net
Chainguard cluster-autoscaler-1.26
Chainguard cluster-autoscaler-1.26-compat
Wolfi cluster-autoscaler-1.26
Wolfi cluster-autoscaler-1.26-compat
Chainguard cluster-autoscaler-1.28
Chainguard cluster-autoscaler-1.28-compat
Wolfi cluster-autoscaler-1.28
Wolfi cluster-autoscaler-1.28-compat
Chainguard cluster-autoscaler-1.27
Chainguard cluster-autoscaler-1.27-compat
Wolfi cluster-autoscaler-1.27
Wolfi cluster-autoscaler-1.27-compat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2023-1988

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

View original source
Open Source Vulnerabilities GHSA-2wrh-6pvc-2jm9

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

View original source
Open Source Vulnerabilities CVE-2023-3978

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

View original source

05 / REFERENCES

Further evidence