Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
| Software | From | Fixed in |
|---|---|---|
| golang / networking | - | 0.13.0 |
golang.org/x/net
|
- | 0.13.0 |