GHSA-2wrh-6pvc-2jm9
GitHub Security Advisory
Improper rendering of text nodes in golang.org/x/net/html
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Affected Packages
Go
golang.org/x/net
Affected versions:
0
(fixed in 0.13.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 18, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.