Junglewise Threat Intelligence

CVE-2026-27136: Golang x/net/html XSS via duplicate attribute parsing

CVE-2026-27136 · Severity: medium · CVSS 6.1 · Published 2026-05-22

Technologies: golang.org/x/net (Go). Vendors: Go.

Executive brief

A vulnerability in the Go programming language's standard networking library can allow attackers to bypass security filters on websites. By providing specially crafted HTML with duplicate attributes, an attacker can trick the system into executing malicious scripts in a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the golang.org/x/net/html package due to improper handling of duplicate attributes during HTML parsing. When the parser encounters multiple identical attributes, it may produce an unexpected HTML tree structure that differs from how a web browser would interpret the same markup. This discrepancy allows an attacker to bypass HTML sanitizers that rely on the library's Parse or ParseFragment functions, leading to the execution of malicious scripts when the resulting tree is rendered. The issue affects versions of the package prior to v0.55.0 and is triggered when processing arbitrary, untrusted HTML input.

Affected products

  • Golang net/html before v0.55.0

Timeline

  • 2026-05-21: other: Issue opened on GitHub
  • 2026-05-22: advisory: NVD and Go Project published advisory
  • 2026-05-22: patched: Fix released in version 0.55.0

References

Related threats