CLEANSTART-2026-LZ15854

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LZ15854.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-LZ15854
Upstream
Published
2026-10-02T00:35:54Z
Modified
2026-10-02T02:30:02Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree
Details

Security vulnerability affects the consul package. Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree.

References

Affected packages

CleanStart / consul

Package

Name
consul

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.21.5-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LZ15854.json"