Beveiligingsadvies

CVE-2026-39823

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-07 19:41:19
Laatst bijgewerkt 2026-05-08 14:05:55
Toegewezen door Go
CVSS-score 6.1
Status PUBLISHED

Beschrijving

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.