CVE-2026-25681

MEDIUM

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Title source: cna
STIX 2.1

Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (2)
golang/net < 0.55.0
golang.org/x/net/golang.org/x/net/html < 0.55.0
Published May 22, 2026
Tracked Since May 22, 2026