QSearchQSearch

CVE-2026-25681

6.1 MEDIUM

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree

Published: 2026-05-22 · Last updated: 2026-05-29

Severity and scoring

CVSS
6.1 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE
CWE-1021

Affected products

VendorProduct
golangnet

Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-42506 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree (6.1 MEDIUM)
  • CVE-2026-42502 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree (6.1 MEDIUM)
  • CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label (9.6 CRITICAL)
  • CVE-2026-27136 Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree (6.1 MEDIUM)
  • CVE-2026-25680 Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service (6.5 MEDIUM)

Same CWE

  • CVE-2026-28577 In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack (7.8 HIGH)
  • CVE-2026-0061 In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overla... (5.9 MEDIUM)
  • CVE-2026-0036 In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack (7.8 HIGH)
  • CVE-2026-21785 A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to defin... (4.0 MEDIUM)
  • CVE-2026-9396 A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426 (3.7 LOW)