« Volver al listado

CVE-2026-42502

Estado: AnalizadaMedia (6.1)—

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42502",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42502",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-22T17:16:33.414557Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "golang.org/x/net",
          "product": "golang.org/x/net/html",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.55.0",
              "versionType": "semver"
            }
          ],
          "packageName": "golang.org/x/net/html",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "parser.parse"
            },
            {
              "name": "Parse"
            },
            {
              "name": "ParseFragment"
            },
            {
              "name": "ParseFragmentWithOptions"
            },
            {
              "name": "ParseWithOptions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-22T16:16:20.587",
  "references": [
    {
      "url": "https://go.dev/cl/781701",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/79572",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8",
      "tags": [
        "Mailing List"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2026-5027",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1021"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."
    },
    {
      "lang": "es",
      "value": "Procesar HTML arbitrario que luego se renderiza usando Render puede resultar en un árbol HTML inesperado. Esto puede ser explotado para ejecutar ataques XSS en aplicaciones que intentan sanear el HTML de entrada antes de renderizar."
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:golang:net:*:*:*:*:*:go:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38C86E7B-A1CA-4670-B113-FC9585261F6F",
              "versionEndExcluding": "0.55.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@golang.org"
}