Red Hat disclosed and patched two medium-severity cross-site scripting flaws in Go's html/template package, tracked as CVE-2026-39823 and CVE-2026-39826. The bugs were reported on 2026-05-07 and affect template escaping logic in cases where developers rely on html/template to safely handle untrusted data in HTML output.
CVE-2026-39823 stems from improper URL escaping in a meta tag's content attribute when ASCII whitespace appears around the = character, which can let malicious input bypass protections and trigger XSS. CVE-2026-39826 affects escaping inside <script> tags when the type attribute is empty or contains ASCII whitespace, causing inserted data to be escaped incorrectly. Red Hat said fixes were released through multiple RHSA advisories for RHEL 8, 9, and 10, including RHEL 10.0 EUS and RHEL 9.6 EUS.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Rocky Linux published RLSA-2026:63332 for Rocky Linux 10 buildah packages, remediating seven Go standard-library flaws. The advisory includes CVE-2026-33810, a crypto/x509 certificate-validation bypass, plus XSS and denial-of-service issues including CVE-2026-42499 and CVE-2026-56858.
Red Hat published RHSA-2026:62754 to update RHEL 9 osbuild-composer packages, addressing seven Go standard-library denial-of-service flaws and the Go html/template XSS flaw CVE-2026-56858. The Important-rated advisory includes CVE-2026-42499 and CVE-2026-39820, among other vulnerabilities, affecting packages such as osbuild-composer-core, osbuild-composer-dnf-json, and osbuild-composer-worker.
Red Hat tracked CVE-2026-42499 as Bug 2467809 after OSIDB Bzimport reported a high-severity Go net/mail denial-of-service issue caused by pathological RFC 5322 email-address parsing in consumePhrase. Red Hat states the issue was addressed across RHEL 8, 9, and 10, RHEL EUS releases, and OpenShift Container Platform 4.19.
Red Hat's Bugzilla record says CVE-2026-39826, a Go html/template XSS issue caused by incorrect escaping inside script tags, was reported by OSIDB Bzimport. The report was tracked as Bug 2467826.
Red Hat's Bugzilla record says CVE-2026-39823, a Go html/template XSS issue involving improper URL escaping in a meta tag content attribute, was reported by OSIDB Bzimport. The report was tracked as Bug 2467811.
A Tenable reference identifies Red Hat Security Advisory RHSA-2026:57649 for RHEL 9 golang as associated with multiple Red Hat Bugzilla records, including 2467811 and 2467826. The provided notice does not specify the CVEs, fixed package version, or other technical remediation details.
Red Hat states both CVE-2026-39823 and CVE-2026-39826 were addressed in Red Hat Enterprise Linux 8, 9, 10, RHEL 10.0 Extended Update Support, and RHEL 9.6 Extended Update Support through advisories including RHSA-2026:22112, RHSA-2026:22120, RHSA-2026:22121, RHSA-2026:49702, and RHSA-2026:49712. The references do not explicitly anchor a date for when those advisories were issued.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.