Junglewise Threat Intelligence

CVE-2026-42506: Golang net/html Cross-Site Scripting via incorrect namespaced element parsing

CVE-2026-42506 · Severity: medium · CVSS 6.1 · Published 2026-05-22

Technologies: golang.org/x/net (Go). Vendors: Go.

Executive brief

A vulnerability in a common Go programming library used for processing web content could allow attackers to execute malicious scripts in a user's browser. This occurs because the library incorrectly handles certain types of web code, potentially bypassing security filters designed to clean up dangerous content. If exploited, this could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the golang.org/x/net/html package due to improper handling of namespaced elements within foreign content (such as SVG or MathML) during parsing. When arbitrary HTML is parsed and subsequently rendered using the Render function, the resulting HTML tree may differ from the expected structure. This discrepancy allows attackers to bypass HTML sanitization libraries that rely on the parser's output, leading to the execution of malicious scripts. The issue affects the Parse, ParseFragment, and related functions. A fix is available in version v0.55.0 of the package.

Affected products

  • Golang net/html before v0.55.0

Timeline

  • 2026-05-21: other: Issue opened on GitHub
  • 2026-05-22: disclosed: Vulnerability published by Go Project
  • 2026-05-22: advisory: NVD entry created

References

Related threats