HTML Meta Tag Vulnerability in Go Programming Language
CVE-2026-27142
What is CVE-2026-27142?
The vulnerability arises from improper handling of URLs within the content attribute of HTML meta tags in the Go programming language. When an action inserts a URL that is not escaped, it poses a risk for XSS attacks, especially if the meta tag includes an http-equiv attribute set to 'refresh'. This issue can lead to unintended consequences, allowing attackers to execute arbitrary scripts in the context of a user's browser session. A new GODEBUG setting, htmlmetacontenturlescape, has been introduced to control the escaping behavior for URLs, providing developers with an option to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
html/template 0 < 1.25.8
html/template 1.26.0-0 < 1.26.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
