CVE-2026-39823
MediumAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4,006
- of 17,805 indexed, latest versions
- Container images
- 4,576
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Bypass of meta content URL escaping causes XSS in html/template
Carried by container images the latest versions of 4,006 of 17,805 indexed charts deploy, on 4,576 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,576 |
- OSV records
- DEBIAN-CVE-2026-39823GO-2026-4982
- Also known as
- BIT-golang-2026-39823
Charts affected
4,006 by stars
Container images carrying it
4,576 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chaosnative/ | 72ee352bc333 | stdlib | 1.25.10 | 1 |
| chaosnative/ | 62cf6adc355e | stdlib | 1.25.10 | 1 |
| chaosnative/ | e7bcff4a20c0 | stdlib | 1.25.10 | 1 |
| charmcli/ | 39523c1a6ba8 | stdlib | 1.25.10 | 1 |
| chibisafe/ | 3da4fcbc1a18 | stdlib | 1.25.10 | 1 |
| chirpstack/ | e0b23dfd24d6 | stdlib | 1.25.10 | 1 |
| chirpstack/ | fb7667fe037f | stdlib | 1.25.10 | 1 |
| chirpstack/ | ce3f2cdca8a9 | stdlib | 1.25.10 | 1 |
| chirpstack/ | c0bbbb7a3f1e | stdlib | 1.25.10 | 1 |
| chirpstack/ | c98d7fe06bce | stdlib | 1.25.10 | 1 |
| chocobozzz/ | 052712130691 | stdlib | 1.25.10 | 1 |
| chriseaton/ | 54c3384ce701 | stdlib | 1.25.10 | 1 |
| chrislusf/ | 634b094b2183 | stdlib | 1.25.10 | 1 |
| chrislusf/ | ed80f00fde46 | stdlib | 1.25.10 | 1 |
| chriswells0/ | f3918ec8471c | stdlib | 1.25.10 | 1 |
| circleci/ | 4d8d0ae5efc3 | stdlib | 1.25.10 | 1 |
| circleci/ | 9bdc62f02162 | stdlib | 1.25.10 | 1 |
| ciscolabs/ | 36d02faad958 | stdlib | 1.25.10 | 1 |
| ckan/ | ef8e5d3e6be1 | stdlib | 1.25.10 | 1 |
| clastix/ | 43d301afbca8 | stdlib | 1.25.10 | 1 |
| clickhouse/ | 512bb8a21483 | stdlib | 1.25.10 | 1 |
| clickhouse/ | dc5658853ce1 | stdlib | 1.25.10 | 1 |
| cloudbees/ | 1d44fb4f799b | stdlib | 1.25.10 | 1 |
| cloudbees/ | 8f102ef0383a | stdlib | 1.25.10 | 1 |
| cloudecho/ | f76ede067ab9 | stdlib | 1.25.10 | 1 |
| cloudentity/ | 9402ec4b5016 | stdlib | 1.25.10 | 1 |
| cloudentity/ | 8a1890eb8265 | stdlib | 1.25.10 | 1 |
| cloudentity/ | ee83cdd45b7b | stdlib | 1.25.10 | 1 |
| cloudentity/ | 5728654cecb7 | stdlib | 1.25.10 | 1 |
| cloudentity/ | 8ca94ae6acf4 | stdlib | 1.25.10 | 1 |
| cloudentity/ | c04eb10c77b7 | stdlib | 1.25.10 | 1 |
| cloudflare/ | 14d9c6b01b29 | stdlib | 1.25.10 | 1 |
| cloudflare/ | 5d5f70a59d5e | stdlib | 1.25.10 | 1 |
| cloudflare/ | c18744ae1767 | stdlib | 1.25.10 | 1 |
| cloudflare/ | eb5c9324efe3 | stdlib | 1.25.10 | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | stdlib | 1.25.10 | 1 |
| cloudposse/ | 0d9507e8a760 | stdlib | 1.25.10 | 1 |
| cloudreve/ | f7a464100bf6 | stdlib | 1.25.10 | 1 |
| cmacrae/ | fc5fecba436e | stdlib | 1.25.10 | 1 |
| cmacrae/ | dec8d490fe40 | stdlib | 1.25.10 | 1 |
| cockroachdb/ | 983312754620 | stdlib | 1.25.10 | 1 |
| codecov/ | de483faad6e5 | stdlib | 1.25.10 | 1 |
| codenotary/ | 7c85d7cc4f22 | stdlib | 1.25.10 | 1 |
| codercom/ | 1e2cc688008e | stdlib | 1.25.10 | 1 |
| codercom/ | 47605610ad8d | stdlib | 1.25.10 | 1 |
| coderenvs/ | 1deffc4670e6 | stdlib | 1.25.10 | 1 |
| codeskyblue/ | caa862590e34 | stdlib | 1.25.10 | 1 |
| cometbft/ | 22c2ac018f40 | stdlib | 1.25.10 | 1 |
| conduction/ | 9cfeeb6c7c20 | stdlib | 1.25.10 | 1 |
| conduction/ | c36094a41369 | stdlib | 1.25.10 | 1 |