Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade soci-snapshotterUpgrade dockerUpgrade runfinch-finchUpgrade nerdctl-debuginfoUpgrade ecs-initUpgrade docker-debuginfoUpgrade containerd-stressUpgrade nerdctlUpgrade containerdUpgrade containerd-debuginfo | Jun 16, 2026 | Jun 16, 2026 |
| Amazon_linux_2023 | — | Upgrade containerd-stressUpgrade soci-snapshotterUpgrade containerd-debugsourceUpgrade containerd-debuginfoUpgrade containerdUpgrade containerd-stress-debuginfoUpgrade runfinch-finchUpgrade nerdctlUpgrade credentials-fetcherUpgrade docker-debugsourceUpgrade ecs-initUpgrade dockerUpgrade docker-debuginfo | Jun 15, 2026 | May 22, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub