Security Advisory

CVE-2026-39826

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-07 19:41:19
Last updated 2026-05-08 14:05:05
Assigner Go
CVSS score not scored
State PUBLISHED

Description

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.