Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value refresh. A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow url= by setting htmlmetacontenturlescape=0.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Golang-1.25 | Ubuntu | upstream | * |
| Golang-1.26 | Ubuntu | upstream | * |