CVE-2026-27136
published 2026-05-22CVE-2026-27136: Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.22%
12.8th percentile
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Affected
471 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| advanced-cluster-security | rhacs-operator-bundle | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-rhel9-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel9 | — | — |
| ansible-automation-platform-26 | receptor-rhel9 | — | — |
| ansible-automation-platform-27 | receptor-rhel9 | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| cert-manager | cert-manager-istio-csr-rhel9 | — | — |
| cert-manager | cert-manager-trust-manager-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-acmesolver-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-compliance-operator-bundle | — | — |
| compliance | openshift-file-integrity-operator-bundle | — | — |
| compliance | openshift-file-integrity-rhel8-operator | — | — |
| compliance | openshift-selinuxd-rhel10 | — | — |
| compliance | openshift-selinuxd-rhel8 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvelistv5v3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
vendor_redhat·2026-05-22·CVSS 6.1
CVE-2026-27136 [MEDIUM] CWE-79 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
A flaw was found in golang.org/x/net/html. When arbitrary HTML is parsed and then rendered, it can result in an unexpected HTML tree. This allows an attacker to bypass HTML sanitization mechanisms, leading to Cross-Site Scripting (XSS) attacks in applications. Such attacks can result in information disclosure or arbitrary code execution.
Statement: This vulnerability in `golang.org/x/net/html` is rated as Important. It allows for Cross-Site Scripting (XSS) attacks by enabling an a
GHSA
GHSA-m9x8-m34x-fj9q: Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree
ghsa_unreviewed·2026-05-26
CVE-2026-27136 [MEDIUM] GHSA-m9x8-m34x-fj9q: Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
VulDB
x-net up to 0.54.x on Go cross site scripting
vuldb·2026-05-22
CVE-2026-27136 [LOW] x-net up to 0.54.x on Go cross site scripting
A vulnerability identified as problematic has been detected in x-net up to 0.54.x on Go. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-27136. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
CVEList
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
cvelistv5·2026-05-22·CVSS 6.1
CVE-2026-27136 [MEDIUM] Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
No detection rules found.
No public exploits indexed.
2026-05-22
Published