Red Hat Security Advisory: Red Hat Hardened Images RPM Release
Red Hat Hardened Images RPM Release
AI Analysis
Technical Summary
An input escaping flaw exists in the golang html/template module where URLs inserted into the content attribute of HTML meta tags are not properly escaped if the meta tag also has an http-equiv attribute with the value "refresh". This can enable cross-site scripting (CWE-79) attacks. Red Hat Hardened Images RPMs are affected. A new GODEBUG setting (htmlmetacontenturlescape) allows disabling escaping of URLs in meta content attributes, but this is not considered a sufficient mitigation by Red Hat. No patches or fixes have been released as of the advisory date. The vulnerability could allow execution of unauthorized code or disclosure of sensitive information via XSS, but no known exploits are reported in the wild.
Potential Impact
The vulnerability enables cross-site scripting attacks by failing to escape URLs in meta refresh tags, potentially allowing attackers to execute unauthorized scripts in the context of affected web applications. This can lead to disclosure of sensitive information such as cookies or session data, and possibly unauthorized actions performed on behalf of users. The impact is rated medium by Red Hat. No active exploitation has been reported.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Red Hat states that existing mitigation options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for future updates. The GODEBUG environment variable htmlmetacontenturlescape can be set to 0 to disable URL escaping in meta content attributes, but this is not recommended as a reliable mitigation. No additional vendor-recommended mitigations are provided at this time.
Red Hat Security Advisory: Red Hat Hardened Images RPM Release
Description
Red Hat Hardened Images RPM Release
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An input escaping flaw exists in the golang html/template module where URLs inserted into the content attribute of HTML meta tags are not properly escaped if the meta tag also has an http-equiv attribute with the value "refresh". This can enable cross-site scripting (CWE-79) attacks. Red Hat Hardened Images RPMs are affected. A new GODEBUG setting (htmlmetacontenturlescape) allows disabling escaping of URLs in meta content attributes, but this is not considered a sufficient mitigation by Red Hat. No patches or fixes have been released as of the advisory date. The vulnerability could allow execution of unauthorized code or disclosure of sensitive information via XSS, but no known exploits are reported in the wild.
Potential Impact
The vulnerability enables cross-site scripting attacks by failing to escape URLs in meta refresh tags, potentially allowing attackers to execute unauthorized scripts in the context of affected web applications. This can lead to disclosure of sensitive information such as cookies or session data, and possibly unauthorized actions performed on behalf of users. The impact is rated medium by Red Hat. No active exploitation has been reported.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Red Hat states that existing mitigation options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for future updates. The GODEBUG environment variable htmlmetacontenturlescape can be set to 0 to disable URL escaping in meta content attributes, but this is not recommended as a reliable mitigation. No additional vendor-recommended mitigations are provided at this time.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:5192
- Cve Count
- 1
Threat ID: 6a4049d527e9c7971982d056
Added to database: 06/27/2026, 22:08:21 UTC
Last enriched: 08/16/2026, 17:42:17 UTC
Last updated: 09/10/2026, 19:24:59 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.