Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27136

35
FAUCET Score

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

First published: May 22, 2026Last modified: May 22, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 0.55.0CPE matchmatch criteria
cpe:2.3:a:golang:net:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 6th percentile among its peer group of 26,208 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (52)

microsoftpatch availablevia msrc
Product: 21358-17084Fixed in: 1.4.0-6
microsoftpatch availablevia msrc
Product: 21359-17084Fixed in: 2.8.1-4
microsoftpatch availablevia msrc
Product: 21378-17084Fixed in: 1.30.10-25
microsoftpatch availablevia msrc
Product: 21414-17084Fixed in: 3.7.0-6
microsoftpatch availablevia msrc
Product: 21278-17084Fixed in: 2.62.0-16
microsoftpatch availablevia msrc
Product: 21281-17084Fixed in: 2.7.5-17
microsoftpatch availablevia msrc
Product: 21007-17084Fixed in: 2.14.1-13
microsoftpatch availablevia msrc
Product: 21008-17084Fixed in: 0.0.10-6
microsoftpatch availablevia msrc
Product: 21256-17084Fixed in: 1.30.10-25
microsoftpatch availablevia msrc
Product: 21299-17084Fixed in: 1.7.1-5
microsoftpatch availablevia msrc
Product: 21013-17084Fixed in: 4.0.2-8
microsoftpatch availablevia msrc
Product: 20981-17084Fixed in: 1.7.7-4
microsoftpatch availablevia msrc
Product: 20984-17084Fixed in: 1.12.15-8
microsoftpatch availablevia msrc
Product: 20985-17084Fixed in: 8.7.11-6
microsoftpatch availablevia msrc
Product: 20986-17084Fixed in: 0.5.1-4
microsoftpatch availablevia msrc
Product: 21475-17084Fixed in: 1.4.0-6
microsoftpatch availablevia msrc
Product: 21319-17084Fixed in: 2.1.6-3
microsoftpatch availablevia msrc
Product: 21276-17084Fixed in: 1.62.0-5
microsoftpatch availablevia msrc
Product: 20991-17084Fixed in: 1.32.0-6
microsoftpatch availablevia msrc
Product: 21476-17084Fixed in: 2.8.1-4
microsoftpatch availablevia msrc
Product: 21271-17084Fixed in: 0.14.0-13
microsoftpatch availablevia msrc
Product: 21272-17084Fixed in: 2.27.0-11
microsoftpatch availablevia msrc
Product: 20966-17084Fixed in: 1.9.5-14
microsoftpatch availablevia msrc
Product: 21015-17084Fixed in: 0.12.0-6
microsoftpatch availablevia msrc
Product: 21020-17084Fixed in: 3.7.0-6
microsoftpatch availablevia msrc
Product: 21258-17084Fixed in: 1.31.0-21
microsoftpatch availablevia msrc
Product: azl3 cloud-provider-kubevirt 0.5.1-3 on Azure Linux 3.0Fixed in: 0.5.1-4
microsoftpatch availablevia msrc
Product: azl3 cni-plugins 1.4.0-5 on Azure Linux 3.0Fixed in: 1.4.0-6
microsoftpatch availablevia msrc
Product: azl3 containerd2 2.1.6-2 on Azure Linux 3.0Fixed in: 2.1.6-3
microsoftpatch availablevia msrc
Product: azl3 containerized-data-importer 1.62.0-3 on Azure Linux 3.0Fixed in: 1.62.0-5
microsoftpatch availablevia msrc
Product: azl3 dasel 2.8.1-4 on Azure Linux 3.0Fixed in: 2.8.1-4
microsoftpatch availablevia msrc
Product: azl3 influxdb 2.7.5-15 on Azure Linux 3.0Fixed in: 2.7.5-17
microsoftpatch availablevia msrc
Product: azl3 kube-vip-cloud-provider 0.0.10-5 on Azure Linux 3.0Fixed in: 0.0.10-6
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-23 on Azure Linux 3.0Fixed in: 1.30.10-25
microsoftpatch availablevia msrc
Product: azl3 kubevirt 1.7.1-2 on Azure Linux 3.0Fixed in: 1.7.1-5
microsoftpatch availablevia msrc
Product: azl3 prometheus-adapter 0.12.0-5 on Azure Linux 3.0Fixed in: 0.12.0-6
microsoftpatch availablevia msrc
Product: azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0Fixed in: 1.7.7-4
microsoftpatch availablevia msrc
Product: azl3 cert-manager 1.12.15-6 on Azure Linux 3.0Fixed in: 1.12.15-8
microsoftpatch availablevia msrc
Product: azl3 cf-cli 8.7.11-5 on Azure Linux 3.0Fixed in: 8.7.11-6
microsoftpatch availablevia msrc
Product: azl3 cni-plugins 1.4.0-6 on Azure Linux 3.0Fixed in: 1.4.0-6
microsoftpatch availablevia msrc
Product: azl3 cri-tools 1.32.0-4 on Azure Linux 3.0Fixed in: 1.32.0-6
microsoftpatch availablevia msrc
Product: azl3 dasel 2.8.1-3 on Azure Linux 3.0Fixed in: 2.8.1-4
microsoftpatch availablevia msrc
Product: azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0Fixed in: 0.14.0-13
microsoftpatch availablevia msrc
Product: azl3 docker-compose 2.27.0-9 on Azure Linux 3.0Fixed in: 2.27.0-11
microsoftpatch availablevia msrc
Product: azl3 gh 2.62.0-15 on Azure Linux 3.0Fixed in: 2.62.0-16
microsoftpatch availablevia msrc
Product: azl3 keda 2.14.1-11 on Azure Linux 3.0Fixed in: 2.14.1-13
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-25 on Azure Linux 3.0Fixed in: 1.30.10-25
microsoftpatch availablevia msrc
Product: azl3 multus 4.0.2-7 on Azure Linux 3.0Fixed in: 4.0.2-8
microsoftpatch availablevia msrc
Product: azl3 packer 1.9.5-13 on Azure Linux 3.0Fixed in: 1.9.5-14
microsoftpatch availablevia msrc
Product: azl3 sriov-network-device-plugin 3.7.0-5 on Azure Linux 3.0Fixed in: 3.7.0-6
microsoftpatch availablevia msrc
Product: azl3 sriov-network-device-plugin 3.7.0-6 on Azure Linux 3.0Fixed in: 3.7.0-6
microsoftpatch availablevia msrc
Product: azl3 telegraf 1.31.0-19 on Azure Linux 3.0Fixed in: 1.31.0-21

Vendor Advisories (1)

microsoft2026-May/CVE-2026-27136Moderate

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

May 12, 2026

References

go.dev / cl/781685
Issue Tracking
go.dev / issue/79575
Issue Tracking
groups.google.com / g/golang-announce/c/iI-mYSI0lu8
Mailing List
pkg.go.dev / vuln/GO-2026-5030
Vendor Advisory