CVE-2026-27136
UnscoredAdvisory
Published 22 May 2026In the index since 5 Sept 2026
- Severity
- Unscored
- worst across findings
- CVSS
- —
- base score, highest
- EPSS
- 0.002
- 13th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,078
- of 17,821 indexed, latest versions
- Container images
- 3,727
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Carried by container images the latest versions of 3,078 of 17,821 indexed charts deploy, on 3,727 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+220 more | 0.55.0 | 3,727 |
- OSV records
- GO-2026-5030
Charts affected
3,078 by stars
Container images carrying it
3,727 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| public.ecr.aws/ | fe383abf1dbc | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | b9d047442ce2 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 491c39346b19 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 6c2f0585cd6c | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 1d548e59c2c8 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 6458fcd61e0c | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 5ca2d500d374 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | a94d2d4aae85 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | e97e0e7a2088 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 14f3dfbc0225 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | b9a7d6bc2a0c | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 75a6d5ce3bd3 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 4cd274463e6b | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 71697b5ff713 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | cfc92cc2de65 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 849e235e2d3e | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 9083e60c38bc | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 651739583336 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 86380a01587d | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | efcecf98b912 | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 920b8f901aef | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 573779e57fae | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 077e4e57e41c | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 988c8e1a273a | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 08c90bd040bf | golang.org/ | 0.55.0 | 1 |
| public.ecr.aws/ | 43d051eed000 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 3c269612053f | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 807c1bb67086 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 578934444f04 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | a8837b00ba1c | golang.org/ | 0.55.0 | 1 |
| quay.io/ | e618a3ed6436 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 1ef2b53c98fd | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 9ca307b30080 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 56425d4f8b9c | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 89990b146824 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 7302e0c8e5a7 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 0deb1a1c9176 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 5b6701d8fb31 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 95b5cf7ba6fe | golang.org/ | 0.55.0 | 1 |
| quay.io/ | a36ab0c0860c | golang.org/ | 0.55.0 | 1 |
| quay.io/ | acaf37352569 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 577fc18f86ad | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 6efd1cb89dc1 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 91b9825f09a8 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | a83d2699ae53 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 0d614816c4b7 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 3c56f354fac5 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | a09814522a72 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | cf8faa986789 | golang.org/ | 0.55.0 | 1 |
| quay.io/ | 51dded00137a | golang.org/ | 0.55.0 | 1 |