The HTML parser mishandled certain HTML elements in foreign content, causing
them to be incorrectly rendered. This can lead to XSS when rendering parsed
HTML.
Thanks to Tristan Madani for reporting this issue.
This is CVE-2026-42502 and Go issue https://go.dev/issue/79572.
This was a PRIVATE track issue, tracked in http://b/496304862.
The HTML parser mishandled certain HTML elements in foreign content, causing
them to be incorrectly rendered. This can lead to XSS when rendering parsed
HTML.
Thanks to Tristan Madani for reporting this issue.
This is CVE-2026-42502 and Go issue https://go.dev/issue/79572.
This was a PRIVATE track issue, tracked in http://b/496304862.