CVE-2026-27136: Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Other sources
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.8.1-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.12.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.4.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.30.10-25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.7.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.0.10-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.1-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.9.5-14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.62.0-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.7.5-17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.32.0-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.14.1-13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.31.0-21 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.12.15-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.7.7-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.14.0-13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.62.0-16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.2-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.1.6-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.27.0-11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.7.11-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.5.1-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27136?
CVE-2026-27136 has a risk rating of 42, indicating a significant vulnerability.
How does CVE-2026-27136 allow for XSS attacks?
CVE-2026-27136 can lead to XSS attacks by allowing the rendering of unexpected HTML due to duplicate attributes.
Which software is affected by CVE-2026-27136?
CVE-2026-27136 affects the golang.org/x/net/html package.
What precaution should developers take regarding CVE-2026-27136?
Developers should avoid parsing arbitrary HTML and ensure proper sanitization of input before rendering.
When was CVE-2026-27136 published?
CVE-2026-27136 was published on May 22, 2026.