Disclosure summary
Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.
Source-reported weakness categories
CWE-79
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Apr
Open original source · Updated Sep 24, 2026
Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities. This allows an attacker to bypass protocol filtering by encoding dangerous schemes using HTML5 named character references. For example, a payload such as javascript:alert(1) is not recognized as dangerous during validation, leading to arbitrary script execution in the context of applications that render the URL.
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 6.1
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | cbl2 gh 2.13.0-26 on CBL Mariner 2.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 telegraf 1.31.0-17 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 gh 2.62.0-15 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 telegraf 1.31.0-19 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | cbl2 telegraf 1.29.4-22 on CBL-Mariner 2.0 | (MSRC status code 3) |
| Microsoft update guide | azl3 gh 2.62.0-13 on Azure Linux 3.0 | (MSRC status code 3) |
| Microsoft update guide | cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0 | (MSRC status code 3) |
| Microsoft update guide | cbl2 gh 2.13.0-26 on CBL-Mariner 2.0 | (MSRC status code 3) |
Vendor remediation references
- CBL-Mariner Releases · build 1.31.0-19 · product IDs 21127-17084, 21258-17084
- Vendor guidance · product IDs 21127-17084, 21258-17084
- CBL-Mariner Releases · build 2.62.0-15 · product IDs 21278-17084, 20997-17084
- Vendor guidance · product IDs 21278-17084, 20997-17084
- Release Notes · product IDs 21126-21692, 21224-21692
- Vendor guidance · product IDs 21126-21692, 21224-21692
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2026-04-18T21:01:39-04:00
MODIFIED 2026-09-24T21:53:12-04:00
INGESTED 2026-10-08T12:45:03-04:00