Description
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Affected products
- golang.org/x/net / golang.org/x/net/html0 – 0.13.0
References
Updated 10m ago · 8 sources