<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Injection on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/injection/</link><description>Recent content in Injection on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 08:40:41 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/injection/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-25681: Go net/html DOCTYPE Parsing Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-25681-golang-net-html-doctype-character-reference-azure/</link><pubDate>Thu, 18 Jun 2026 08:40:41 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-25681-golang-net-html-doctype-character-reference-azure/</guid><description>CVE-2026-25681 affects golang.org/x/net/html, causing incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25681">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-25681 is a vulnerability in the Go standard library package golang.org/x/net/html, where character references within DOCTYPE nodes are handled incorrectly. This can lead to malformed HTML parsing behaviour, potentially enabling injection or bypass attacks in applications that rely on this library for HTML processing. Any Azure services or workloads built with affected versions of the Go net/html package may be exposed.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Go-based services and container images for dependencies on golang.org/x/net/html and update to the patched version as soon as it is available. Pay particular attention to internal tooling, API gateways, or microservices that parse untrusted HTML input, as these represent the highest risk surface.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25681">CVE-2026-25681 Invoking  incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html</a></p>
]]></content:encoded></item></channel></rss>