FlawAtlas
Search the atlas
CVE-2026-42506 Moderate

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Exploit probability 0.2%
Published May 22, 2026
Required by Not available
Last source change May 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

54 explicit affected versions

Go golang.org/x/net

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2026-5025

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

View original source
Open Source Vulnerabilities CVE-2026-42506

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

View original source

05 / REFERENCES

Further evidence