FlawAtlas
Search the atlas
CVE-2026-42502 Moderate

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Exploit probability 0.2%
Published May 22, 2026
Required by Not available
Last source change September 1, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

54 explicit affected versions

Go golang.org/x/net

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1
related RHSA-2026:59560
related RHSA-2026:59562
related RHSA-2026:61585

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-42502

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

View original source
Open Source Vulnerabilities GO-2026-5027

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

View original source

05 / REFERENCES

Further evidence