)]}'
{
  "commit": "a452f3cc17168a60bc3f439a3ae0fcffc32eca0e",
  "tree": "e38467e133478793a05b2417fc09baefacff2cca",
  "parents": [
    "f8651996b24ba47d89dd9eb97fd47758e6d1886f"
  ],
  "author": {
    "name": "Roland Shoemaker",
    "email": "roland@golang.org",
    "time": "Fri May 08 12:09:06 2026 -0700"
  },
  "committer": {
    "name": "Gopher Robot",
    "email": "gobot@golang.org",
    "time": "Thu May 21 18:12:39 2026 -0700"
  },
  "message": "html: ignore duplicate attributes during tokenization\n\nDuring tokenization ignore attributes with names we\u0027ve already seen,\nper WHATWG 13.2.5.33. This removes a parser misalignment that could be\nleveraged to confuse sanitizers.\n\nThanks to ensy for reporting this issue.\n\nFixes CVE-2026-27136\n\nChange-Id: Ib0a3edb8dbea35c431f74f8b0bbe6229625d7e1f\nReviewed-on: https://go-review.googlesource.com/c/net/+/781685\nReviewed-by: Neal Patel \u003cnealpatel@google.com\u003e\nReviewed-by: Nicholas Husin \u003cnsh@golang.org\u003e\nTryBot-Bypass: Roland Shoemaker \u003croland@golang.org\u003e\nAuto-Submit: Gopher Robot \u003cgobot@golang.org\u003e\nReviewed-by: Nicholas Husin \u003chusin@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "6598c1f7b320fbb19ebf73af7e4c752a4f8ba508",
      "old_mode": 33188,
      "old_path": "html/token.go",
      "new_id": "058dfb2164684d485d19e573cae52e6eec2850bb",
      "new_mode": 33188,
      "new_path": "html/token.go"
    },
    {
      "type": "modify",
      "old_id": "e5ac62308bc47f810c95415dc635f9539fe98b08",
      "old_mode": 33188,
      "old_path": "html/token_test.go",
      "new_id": "5c68ae2820ba94a8a8103e3cbb9b2b4ee12414a2",
      "new_mode": 33188,
      "new_path": "html/token_test.go"
    }
  ]
}
