CVE-2026-39823
MediumAdvisory
Published 7 May 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.003
- 25th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 4,006
- of 17,805 indexed, latest versions
- Container images
- 4,576
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Bypass of meta content URL escaping causes XSS in html/template
Carried by container images the latest versions of 4,006 of 17,805 indexed charts deploy, on 4,576 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+180 more | 1.25.10 | 4,576 |
- OSV records
- DEBIAN-CVE-2026-39823GO-2026-4982
- Also known as
- BIT-golang-2026-39823
Charts affected
4,006 by stars
Container images carrying it
4,576 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| eclipseaerios/ | 18c7f0d101c0 | stdlib | 1.25.10 | 1 |
| eclipseaerios/ | 99d7ff18d416 | stdlib | 1.25.10 | 1 |
| eclipseaerios/ | ab7a04182191 | stdlib | 1.25.10 | 1 |
| eclipseaerios/ | d7ec28bfe735 | stdlib | 1.25.10 | 1 |
| eclipseaerios/ | 2b2c0cf26fd2 | stdlib | 1.25.10 | 1 |
| eclipseaerios/ | 0208743f315e | stdlib | 1.25.10 | 1 |
| eginnovations/ | b8e3e26dca1b | stdlib | 1.25.10 | 1 |
| ekofr/ | 9fdad6f352e0 | stdlib | 1.25.10 | 1 |
| elastic/ | c7a1c63257d0 | stdlib | 1.25.10 | 1 |
| elastisys/ | 509b94f1da55 | stdlib | 1.25.10 | 1 |
| emirozbir/ | 6801ba2a3fc3 | stdlib | 1.25.10 | 1 |
| emirozbir/ | d3a5c1063425 | stdlib | 1.25.10 | 1 |
| empathyco/ | 4f1e26eaacbf | stdlib | 1.25.10 | 1 |
| emqx/ | a8431baa7950 | stdlib | 1.25.10 | 1 |
| emqx/ | fa876f71e5d6 | stdlib | 1.25.10 | 1 |
| emqxecp/ | 4c31d9bec846 | stdlib | 1.25.10 | 1 |
| emqx/ | 53865c1267d9 | stdlib | 1.25.10 | 1 |
| engrmth/ | 6d8464e6f0e8 | stdlib | 1.25.10 | 1 |
| enix/ | f963da81ecf7 | stdlib | 1.25.10 | 1 |
| enketo/ | dcad9c2273f6 | stdlib | 1.25.10 | 1 |
| envoyproxy/ | ec1f06ee29a7 | stdlib | 1.25.10 | 1 |
| envoyproxy/ | 2a9f99d28567 | stdlib | 1.25.10 | 1 |
| envoyproxy/ | 5966cbc14d5d | stdlib | 1.25.10 | 1 |
| envoyproxy/ | 71081616da3e | stdlib | 1.25.10 | 1 |
| envoyproxy/ | b6cb6e16f8c9 | stdlib | 1.25.10 | 1 |
| envoyproxy/ | ede09a75a84c | stdlib | 1.25.10 | 1 |
| epamedp/ | 90f9921d8d58 | stdlib | 1.25.10 | 1 |
| epamedp/ | 96028c86f0dd | stdlib | 1.25.10 | 1 |
| epamedp/ | 616c678ba3e7 | stdlib | 1.25.10 | 1 |
| epamedp/ | 976a662a5e72 | stdlib | 1.25.10 | 1 |
| epamedp/ | 93417e18bb1a | stdlib | 1.25.10 | 1 |
| epamedp/ | 924939850655 | stdlib | 1.25.10 | 1 |
| epamedp/ | b71fb39e0c9e | stdlib | 1.25.10 | 1 |
| epamedp/ | 28ef56bc0ca3 | stdlib | 1.25.10 | 1 |
| epamedp/ | ff25e9fe4419 | stdlib | 1.25.10 | 1 |
| epamedp/ | 5d352199e12e | stdlib | 1.25.10 | 1 |
| epamedp/ | 449a53804699 | stdlib | 1.25.10 | 1 |
| epamedp/ | bd2079b7bfcb | stdlib | 1.25.10 | 1 |
| epamedp/ | d33e938b6d59 | stdlib | 1.25.10 | 1 |
| epamedp/ | 67d896676f45 | stdlib | 1.25.10 | 1 |
| eqalpha/ | fd9351ce27a7 | stdlib | 1.25.10 | 1 |
| erenozcan17/ | 50b4f23422b6 | stdlib | 1.25.10 | 1 |
| erigontech/ | 88706754b627 | stdlib | 1.25.10 | 1 |
| escaping/ | 87fa79255962 | stdlib | 1.25.10 | 1 |
| etejeda/ | 737d58183abc | stdlib | 1.25.10 | 1 |
| ethereum/ | 1f36ca5922a5 | stdlib | 1.25.10 | 1 |
| ethereum/ | 32b878e4144a | stdlib | 1.25.10 | 1 |
| ethereum/ | 6d6d12a40465 | stdlib | 1.25.10 | 1 |
| ethereum/ | 886ec69b35b0 | stdlib | 1.25.10 | 1 |
| ethereum/ | cce21b423165 | stdlib | 1.25.10 | 1 |