CVE-2026-27142

Public on 2026-03-06
Modified on 2026-03-10
Description
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-cloudwatch-agent Pending Fix
Amazon Linux 2023 amazon-cloudwatch-agent Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra amazon-ecr-credential-helper Pending Fix
Amazon Linux 2 - Docker Extra amazon-ecr-credential-helper Pending Fix
Amazon Linux 2 - Ecs Extra amazon-ecr-credential-helper Pending Fix
Amazon Linux 2023 amazon-ecr-credential-helper Pending Fix
Amazon Linux 2 - Core cni-plugins Pending Fix
Amazon Linux 2023 cni-plugins Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra containerd Pending Fix
Amazon Linux 2 - Docker Extra containerd Pending Fix
Amazon Linux 2 - Ecs Extra containerd Pending Fix
Amazon Linux 2023 containerd Pending Fix
Amazon Linux 2023 credentials-fetcher Pending Fix
Amazon Linux 2 - Core cri-tools Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra docker Pending Fix
Amazon Linux 2 - Docker Extra docker Pending Fix
Amazon Linux 2 - Ecs Extra docker Pending Fix
Amazon Linux 2023 docker Pending Fix
Amazon Linux 2 - Ecs Extra ecs-init Pending Fix
Amazon Linux 2023 ecs-init Pending Fix
Amazon Linux 2 - Core golang Pending Fix
Amazon Linux 2023 golang Pending Fix
Amazon Linux 2 - Core golang-github-cpuguy83-go-md2man Not Affected
Amazon Linux 2 - Core golist Pending Fix
Amazon Linux 2023 libcap Pending Fix
Amazon Linux 2 - Core nerdctl Pending Fix
Amazon Linux 2023 nerdctl Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra oci-add-hooks Pending Fix
Amazon Linux 2 - Docker Extra oci-add-hooks Pending Fix
Amazon Linux 2 - Ecs Extra oci-add-hooks Pending Fix
Amazon Linux 2023 oci-add-hooks Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra runc Pending Fix
Amazon Linux 2 - Docker Extra runc Pending Fix
Amazon Linux 2 - Ecs Extra runc Pending Fix
Amazon Linux 2023 runc Pending Fix
Amazon Linux 2 - Docker Extra runfinch-finch Pending Fix
Amazon Linux 2023 runfinch-finch Pending Fix
Amazon Linux 2 - Docker Extra soci-snapshotter Pending Fix
Amazon Linux 2023 soci-snapshotter Pending Fix
Amazon Linux 2023 yq Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N