Bug 2458616 (CVE-2026-5160)
| Summary: | CVE-2026-5160 github.com/yuin/goldmark/renderer/html: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in github.com/yuin/goldmark/renderer/html. This Cross-site Scripting (XSS) vulnerability allows a remote attacker to execute arbitrary scripts in the context of applications that render a malicious URL. The flaw stems from an improper ordering of URL validation and normalization, where the component validates link destinations before resolving HTML entities. This enables an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references, leading to unauthorized code execution.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2458968, 2458969, 2458970, 2458972, 2458973, 2458974, 2458975, 2458978, 2458979, 2458980, 2458981, 2458982, 2458983, 2458985, 2458987, 2458988, 2458989, 2458992, 2458993, 2458995, 2458996, 2458971, 2458976, 2458984, 2458986, 2458991, 2458994, 2458997, 2458998 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-15 06:01:14 UTC
Public upstream commit fixing this issue: https://github.com/yuin/goldmark/commit/cb46bbc4eca29d55aa9721e04ad207c23ccc44f9 |