Repository navigation
html/template: fix bypass for CVE-2026-27142 #78913
Description
Activity
- addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.
on Apr 22, 2026 Change https://go.dev/cl/769920 mentions this issue:
html/template: fix escaping of URLs in meta content attributesRelated Issues
Related Code Changes
(Emoji vote if this was helpful or unhelpful; more detailed feedback welcome in this discussion.)
Hi @gopherbot, please open backport issues for this security issue.
Backport issue(s) opened: #79031 (for 1.25), #79032 (for 1.26).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
- added a commit that references this issue
on Apr 29, 2026 Change https://go.dev/cl/772101 mentions this issue:
[release-branch.go1.25] html/template: fix escaping of URLs in meta content attributesChange https://go.dev/cl/772103 mentions this issue:
[release-branch.go1.26] html/template: fix escaping of URLs in meta content attributes- added a commit that references this issue
on Jul 22, 2026 - added a commit that references this issue
on Sep 4, 2026
CVE-2026-27142 fixed a vulnerability in which URLs were not
correctly escaped inside of a tag's attribute.
If the URL content were to insert ASCII whitespaces around the
=rune inside of the attribute, the escaper wouldfail to similarly escape it, leading to XSS.
Dynamic inputs to a tag's attribute are now
whitespace sanitized prior to escaping.
Thanks to Samy Ghannad for reporting this issue.
This is CVE-2026-39823 and Go issue https://go.dev/issue/78913.
This was a PUBLIC track issue, tracked in http://b/495820486.