CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.
CVE
CVE-2026-39823
Severity
MEDIUM
CVSS
6.1
EPSS
0.31%
Original NVD Description
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.
Related CVEs
Other vulnerabilities affecting the same vendor(s)