CVE-2026-39826
•
published on May 7, 2026
If a trusted template author were to write a script tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the