Published 22 May 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,124
of 17,832 indexed, latest versions
Container images
3,762
deployed by those charts
Fix available
1 of 1
affected package
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Carried by container images the latest versions of 3,124 of 17,832 indexed charts deploy, on 3,762 images.
Affected package
Affected versions
Fixed in
Images
golang.org/x/netgolang
v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+222 more
xonodepoolsxonodepoolsOfficialOfficial: Artifact Hub marks the chart as published by the project itselfVerified publisherVerified publisher: Artifact Hub verified the publisher owns the repository
matrixdb-operatorymatrixOfficialOfficial: Artifact Hub marks the chart as published by the project itselfVerified publisherVerified publisher: Artifact Hub verified the publisher owns the repository
zoo-project-druzoo-projectOfficialOfficial: Artifact Hub marks the chart as published by the project itselfVerified publisherVerified publisher: Artifact Hub verified the publisher owns the repository