REDHAT-BUG-2467811: XSS
Published May 7, 2026
·Updated
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.
Affected Software
1 affected component
Red Hat Red Hat Enterprise Linux
Event History
May 7, 2026
Data Sourced
via Red Hat·08:01 PM
DescriptionSeverityAffected Software