VDB

GO-2026-4603

GO-2026-4603 PUBLISHED CVSS 9.300000190734863 CRITICAL

URLs in meta content attribute actions are not escaped in html/template

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
chainguardgitlab-pages-18.90, 0, 0
chainguardopencost0, 0, 0
chainguardflux-fips-2.6*, *, *
chainguardjson-exporter0, 0, 0
chainguardkuma-2.11*, *, *
chainguardwhereabouts-fips*, *, *
chainguardkubescape-server0, 0, 0
chainguardgcp-compute-persistent-disk-csi-driver-fips-1.190, 0, 0
chainguardgosu-fips*, *, *
chainguardnri-mysql*, *, *
chainguardmetallb*, *, *
chainguardrabbitmq-messaging-topology-operator*, *, *
chainguardaws-sigv4-proxy*, *, *
chainguardgitlab-workhorse-ce-18.9*, *, *
wolfiinflux*, *, *
wolficilium-envoy-1.190, 0, 0
chainguardk8s-metacollector-fips0, 0, 0
wolfiknative-operator-1.210, 0, 0
chainguardsnyk-cli0, 0, 0
chainguardmongodb-k8s-operator-version-upgrade-post-start-hook*

…and 2152 more

Timeline

  • Mar 6, 2026 CVE Published
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›