Junglewise Threat Intelligence

CVE-2026-42502: Google Go x/net/html XSS via incorrect foreign content parsing

CVE-2026-42502 · Severity: medium · CVSS 6.1 · Published 2026-05-22

Technologies: golang.org/x/net (Go). Vendors: Google, Go.

Executive brief

A vulnerability in the Go programming language's standard networking library could allow attackers to execute malicious scripts in a user's browser. This occurs when an application parses and then displays untrusted web content, even if the application tries to clean the content first. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the golang.org/x/net/html package due to improper handling of HTML elements within 'foreign content' (such as SVG or MathML tags). When the parser processes specially crafted HTML and the resulting tree is subsequently rendered using the Render function, it can produce an HTML structure that differs from what security sanitizers expect. This discrepancy allows an attacker to bypass HTML sanitization logic and execute arbitrary JavaScript in the context of the victim's browser. The issue affects the Parse, ParseFragment, and related functions. Users should update to golang.org/x/net v0.55.0 or later to resolve this issue.

Affected products

  • Google golang.org/x/net/html before v0.55.0

Timeline

  • 2026-05-21: other: Issue reported to Go project
  • 2026-05-22: disclosed: CVE published and advisory released
  • 2026-05-22: patched: Fixed in golang.org/x/net v0.55.0

References

Related threats