CVE-2026-39823
ADVISORY - nistSummary
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a tag's attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the attribute, the escaper would fail to similarly escape it, leading to XSS.
Common Weakness Enumeration (CWE)
ADVISORY - nist
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-39823
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
GoLang
CREATED
UPDATED
ADVISORY IDGO-2026-4982
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-