Skip to content

html/template: fix bypass for CVE-2026-27142 #78913

Description

@thatnealpatel

CVE-2026-27142 fixed a vulnerability in which URLs were not
correctly escaped inside of a tag's attribute.
If the URL content were to insert ASCII whitespaces around the
= rune inside of the attribute, the escaper would
fail to similarly escape it, leading to XSS.

Dynamic inputs to a tag's attribute are now
whitespace sanitized prior to escaping.

Thanks to Samy Ghannad for reporting this issue.

This is CVE-2026-39823 and Go issue https://go.dev/issue/78913.


This was a PUBLIC track issue, tracked in http://b/495820486.

Activity

  1. added
    NeedsFixThe path to resolution is known, but the work has not been done.
    BugReportIssues describing a possible bug in the Go implementation.
    on Apr 22, 2026
  2. gopherbot commented on Apr 22, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/769920 mentions this issue: html/template: fix escaping of URLs in meta content attributes

  3. gabyhelp commented on Apr 23, 2026

    @gabyhelp
  4. thatnealpatel commented on Apr 29, 2026

    @thatnealpatel
    MemberAuthor

    Hi @gopherbot, please open backport issues for this security issue.

  5. gopherbot commented on Apr 29, 2026

    @gopherbot
    Contributor

    Backport issue(s) opened: #79031 (for 1.25), #79032 (for 1.26).

    Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.

  6. gopherbot commented on Apr 29, 2026

    @gopherbot
  7. gopherbot commented on Apr 29, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/772101 mentions this issue: [release-branch.go1.25] html/template: fix escaping of URLs in meta content attributes

  8. gopherbot commented on Apr 29, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/772103 mentions this issue: [release-branch.go1.26] html/template: fix escaping of URLs in meta content attributes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

BugReportIssues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.Security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions