v0.35.0-sec.4 fixes CVE-2026-27136 for Go 1.18
release-v0.35.0-sec.4
Upstream: https://go.dev/cl/781685
What's Changed
- [Go 1.18] CVE-2026-27136: html: ignore duplicate attributes during tokenization by @germanparente in #14
Full Changelog: v0.35.0-sec.3...v0.35.0-sec.4