Vulnerability record · CVE-2026-27136 · published 22 May 2026
CVE-2026-27136: Golang net clickjacking vulnerability
Golang · Net
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
Description
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://go.dev/cl/781685 | Issue Tracking |
| https://go.dev/issue/79575 | Issue Tracking |
| https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8 | Mailing List |
| https://pkg.go.dev/vuln/GO-2026-5030 | Vendor Advisory |
Track CVE-2026-27136 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-27136), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.