Bug 2480757 (CVE-2026-27136) - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
Summary: CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Si...
Keywords:
Status: NEW
Alias: CVE-2026-27136
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-22 16:01 UTC by OSIDB Bzimport
Modified: 2026-07-20 16:02 UTC (History)
134 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:37072 0 None None None 2026-07-09 05:14:47 UTC
Red Hat Product Errata RHSA-2026:37123 0 None None None 2026-07-09 07:15:58 UTC
Red Hat Product Errata RHSA-2026:42078 0 None None None 2026-07-20 15:59:23 UTC
Red Hat Product Errata RHSA-2026:42079 0 None None None 2026-07-20 16:02:31 UTC
Red Hat Product Errata RHSA-2026:42080 0 None None None 2026-07-20 15:53:42 UTC

Description OSIDB Bzimport 2026-05-22 16:01:19 UTC
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Comment 3 errata-xmlrpc 2026-07-09 05:14:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:37072 https://access.redhat.com/errata/RHSA-2026:37072

Comment 4 errata-xmlrpc 2026-07-09 07:15:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:37123 https://access.redhat.com/errata/RHSA-2026:37123

Comment 7 errata-xmlrpc 2026-07-20 15:53:35 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.7 for RHEL 9
  Red Hat Ansible Automation Platform 2.7 for RHEL 10

Via RHSA-2026:42080 https://access.redhat.com/errata/RHSA-2026:42080

Comment 8 errata-xmlrpc 2026-07-20 15:59:16 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:42078 https://access.redhat.com/errata/RHSA-2026:42078

Comment 9 errata-xmlrpc 2026-07-20 16:02:24 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:42079 https://access.redhat.com/errata/RHSA-2026:42079


Note You need to log in before you can comment on or make changes to this bug.