CVE-2026-27142
MediumAdvisory
Published 6 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.003
- 26th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,843
- of 17,813 indexed, latest versions
- Container images
- 4,361
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
URLs in meta content attribute actions are not escaped in html/template
Carried by container images the latest versions of 3,843 of 17,813 indexed charts deploy, on 4,361 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+177 more | 1.25.8 | 4,361 |
- OSV records
- DEBIAN-CVE-2026-27142GO-2026-4603
- Also known as
- BIT-golang-2026-27142
Charts affected
3,843 by stars
Container images carrying it
4,361 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| librenms/ | 0920bc9117a8 | stdlib | 1.25.8 | 1 |
| librenms/ | 4f1f3d667cc7 | stdlib | 1.25.8 | 1 |
| librenms/ | 8194a4a9ff49 | stdlib | 1.25.8 | 1 |
| lifailon/ | ea37e4b6b952 | stdlib | 1.25.8 | 1 |
| lightstep/ | c800e05e1eff | stdlib | 1.25.8 | 1 |
| linuxserver/ | 241009026e6f | stdlib | 1.25.8 | 1 |
| linuxserver/ | 938810eca3d3 | stdlib | 1.25.8 | 1 |
| linuxserver/ | 2f4488c9afcd | stdlib | 1.25.8 | 1 |
| linuxserver/ | b7f906899cd3 | stdlib | 1.25.8 | 1 |
| lishimeng/ | 3d5752dac834 | stdlib | 1.25.8 | 1 |
| lishimeng/ | c79a67657baf | stdlib | 1.25.8 | 1 |
| lishimeng/ | 3d00485e64dc | stdlib | 1.25.8 | 1 |
| lishimeng/ | 3e7d05ded625 | stdlib | 1.25.8 | 1 |
| lishimeng/ | 0970dfe5dc8f | stdlib | 1.25.8 | 1 |
| lishimeng/ | 8145c3dc83c8 | stdlib | 1.25.8 | 1 |
| lishimeng/ | 9b2f8be6c7d3 | stdlib | 1.25.8 | 1 |
| lishimeng/ | e0b8d2d8ca28 | stdlib | 1.25.8 | 1 |
| listmonk/ | bf3903d54a46 | stdlib | 1.25.8 | 1 |
| litestream/ | c5a1e1b01916 | stdlib | 1.25.8 | 1 |
| livekit/ | 1ab01641b366 | stdlib | 1.25.8 | 1 |
| livekit/ | ecf1409c75e0 | stdlib | 1.25.8 | 1 |
| livekit/ | 3602a85840d5 | stdlib | 1.25.8 | 1 |
| livekit/ | 8391fd1b834f | stdlib | 1.25.8 | 1 |
| lmierzwa/ | 3751e5eed656 | stdlib | 1.25.8 | 1 |
| lmierzwa/ | d417abe7ddb5 | stdlib | 1.25.8 | 1 |
| localstack/ | 9d278167f2b7 | stdlib | 1.25.8 | 1 |
| loeken/ | 4ce6abc553b3 | stdlib | 1.25.8 | 1 |
| loftsh/ | 310cc7d690f5 | stdlib | 1.25.8 | 1 |
| loftsh/ | 25deb9bd2683 | stdlib | 1.25.8 | 1 |
| loftsh/ | 023b13bf5898 | stdlib | 1.25.8 | 1 |
| logiqai/ | 65b996bc7bdc | stdlib | 1.25.8 | 1 |
| logiqai/ | f5b551bca98e | stdlib | 1.25.8 | 1 |
| logiqai/ | 798306811f2d | stdlib | 1.25.8 | 1 |
| logiqai/ | 3e149f6781b8 | stdlib | 1.25.8 | 1 |
| logiqai/ | 4a746ff04d6a | stdlib | 1.25.8 | 1 |
| longhornio/ | 5b0bc1b88f0c | stdlib | 1.25.8 | 1 |
| longhornio/ | ede61fe2a472 | stdlib | 1.25.8 | 1 |
| longhornio/ | 9f6e5e3be8ab | stdlib | 1.25.8 | 1 |
| longhornio/ | e60f36161511 | stdlib | 1.25.8 | 1 |
| longhornio/ | 5875cef29348 | stdlib | 1.25.8 | 1 |
| louislam/ | 2e478d3170bd | stdlib | 1.25.8 | 1 |
| louislam/ | 059b49d64739 | stdlib | 1.25.8 | 1 |
| louislam/ | 0b55bcb83a1c | stdlib | 1.25.8 | 1 |
| louislam/ | 3d632903e6af | stdlib | 1.25.8 | 1 |
| louislam/ | 4c364ef96aad | stdlib | 1.25.8 | 1 |
| louislam/ | 91e963bfda56 | stdlib | 1.25.8 | 1 |
| louislam/ | 96510915e6be | stdlib | 1.25.8 | 1 |
| louislam/ | 9865163f92c1 | stdlib | 1.25.8 | 1 |
| louislam/ | a4eab252e5a2 | stdlib | 1.25.8 | 1 |
| louislam/ | a84767d7934f | stdlib | 1.25.8 | 1 |