Bug 2480757 (CVE-2026-27136) - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
Summary: CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Si...
Keywords:
Status: NEW
Alias: CVE-2026-27136
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-22 16:01 UTC by OSIDB Bzimport
Modified: 2026-09-03 09:17 UTC (History)
162 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:37072 0 None None None 2026-07-09 05:14:47 UTC
Red Hat Product Errata RHSA-2026:37123 0 None None None 2026-07-09 07:15:58 UTC
Red Hat Product Errata RHSA-2026:42078 0 None None None 2026-07-20 15:59:23 UTC
Red Hat Product Errata RHSA-2026:42079 0 None None None 2026-07-20 16:02:31 UTC
Red Hat Product Errata RHSA-2026:42080 0 None None None 2026-07-20 15:53:42 UTC
Red Hat Product Errata RHSA-2026:48151 0 None None None 2026-07-29 19:54:31 UTC
Red Hat Product Errata RHSA-2026:51112 0 None None None 2026-08-06 16:53:15 UTC
Red Hat Product Errata RHSA-2026:53412 0 None None None 2026-08-11 12:05:07 UTC
Red Hat Product Errata RHSA-2026:53413 0 None None None 2026-08-11 11:35:03 UTC
Red Hat Product Errata RHSA-2026:53415 0 None None None 2026-08-11 12:07:12 UTC
Red Hat Product Errata RHSA-2026:59560 0 None None None 2026-08-25 20:12:29 UTC
Red Hat Product Errata RHSA-2026:59562 0 None None None 2026-08-25 20:05:06 UTC
Red Hat Product Errata RHSA-2026:61585 0 None None None 2026-08-31 14:24:26 UTC
Red Hat Product Errata RHSA-2026:63134 0 None None None 2026-09-03 09:17:22 UTC

Description OSIDB Bzimport 2026-05-22 16:01:19 UTC
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Comment 3 errata-xmlrpc 2026-07-09 05:14:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:37072 https://access.redhat.com/errata/RHSA-2026:37072

Comment 4 errata-xmlrpc 2026-07-09 07:15:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:37123 https://access.redhat.com/errata/RHSA-2026:37123

Comment 7 errata-xmlrpc 2026-07-20 15:53:35 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.7 for RHEL 9
  Red Hat Ansible Automation Platform 2.7 for RHEL 10

Via RHSA-2026:42080 https://access.redhat.com/errata/RHSA-2026:42080

Comment 8 errata-xmlrpc 2026-07-20 15:59:16 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:42078 https://access.redhat.com/errata/RHSA-2026:42078

Comment 9 errata-xmlrpc 2026-07-20 16:02:24 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:42079 https://access.redhat.com/errata/RHSA-2026:42079

Comment 11 errata-xmlrpc 2026-07-29 19:54:24 UTC
This issue has been addressed in the following products:

  Cryostat 4 on RHEL 9

Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151

Comment 13 errata-xmlrpc 2026-08-06 16:53:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:51112 https://access.redhat.com/errata/RHSA-2026:51112

Comment 14 errata-xmlrpc 2026-08-11 11:34:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:53413 https://access.redhat.com/errata/RHSA-2026:53413

Comment 15 errata-xmlrpc 2026-08-11 12:04:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:53412 https://access.redhat.com/errata/RHSA-2026:53412

Comment 16 errata-xmlrpc 2026-08-11 12:07:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:53415 https://access.redhat.com/errata/RHSA-2026:53415

Comment 18 errata-xmlrpc 2026-08-25 20:04:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:59562 https://access.redhat.com/errata/RHSA-2026:59562

Comment 19 errata-xmlrpc 2026-08-25 20:12:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:59560 https://access.redhat.com/errata/RHSA-2026:59560

Comment 20 errata-xmlrpc 2026-08-31 14:24:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:61585 https://access.redhat.com/errata/RHSA-2026:61585

Comment 21 errata-xmlrpc 2026-09-03 09:17:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:63134 https://access.redhat.com/errata/RHSA-2026:63134


Note You need to log in before you can comment on or make changes to this bug.