/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-j8mh-fcpj-frhg

Published

Last updated

https://images.chainguard.dev/security/CGA-j8mh-fcpj-frhg
Package

ansible-operator

Repository

Chainguard

Latest Update
Fixed
Fixed Version

1.37.2-r3

Aliases
  • CVE-2025-22872
  • GHSA-vvgc-356p-c3xw

Severity

Unknown

Summary

golang.org/x/net vulnerable to Cross-site Scripting

Description

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs