Skip to content

x/net/html: incorrect handling of HTML elements in foreign content #79572

Description

@thatnealpatel

The HTML parser mishandled certain HTML elements in foreign content, causing
them to be incorrectly rendered. This can lead to XSS when rendering parsed
HTML.

Thanks to Tristan Madani for reporting this issue.

This is CVE-2026-42502 and Go issue https://go.dev/issue/79572.


This was a PRIVATE track issue, tracked in http://b/496304862.

Metadata

Metadata

Assignees

No one assigned

    Labels

    NeedsFixThe path to resolution is known, but the work has not been done.Securityrelease-blocker

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions