CVE-2026-27136None▾ SunlitInvoking duplicate attributes can cause XSS in golang.org/x/net/html
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
0.2% → 0.2%
Last analysed / modified upstream
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
golang.org/x/net < 0.55.0Upgrade to a patched release:
golang.org/x/net 0.55.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25680Medium· 6.5Go Net HTML parser is vulnerable to denial of service
CVE-2026-25681NoneInvoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
CVE-2022-27664High· 7.5golang.org/x/net/http2 Denial of Service vulnerability
CVE-2018-17847High· 7.5golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2023-3978Medium· 6.1Improper rendering of text nodes in golang.org/x/net/html
CVE-2023-39325High· 7.5HTTP/2 rapid reset can cause excessive work in net/http