Vulnerability Description
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.25.8 |
Related Weaknesses (CWE)
References
- https://go.dev/cl/752081Mailing List
- https://go.dev/issue/77954Issue Tracking
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hkRelease Notes
- https://pkg.go.dev/vuln/GO-2026-4603Vendor Advisory
FAQ
What is CVE-2026-27142?
CVE-2026-27142 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG sett...
How severe is CVE-2026-27142?
CVE-2026-27142 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-27142?
Check the references section above for vendor advisories and patch information. Affected products include: Golang Go.