html: properly render fostered elements in foreign content

When we foster elements under another parent, there are complicated
rules about which namespace may apply. This in particular affects
childTextNodesAreLiteral, which checks if we should be emitting raw
text, or escaped text.

In childTextNodesAreLiteral, check if there is an ancestor which has a
different namespace. If one is found, check if it's an HTML integration
point. If not, treat the node as if it were in its parents namespace, if
so, treat it as HTML.

Thanks to Tristan Madani for reporting this issue.

Fixes CVE-2026-42502

Change-Id: I0ae1780dae335e5f719d7f176cefa83670cfea3d
Reviewed-on: https://go-review.googlesource.com/c/net/+/781701
Reviewed-by: Neal Patel <nealpatel@google.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
TryBot-Bypass: Roland Shoemaker <roland@golang.org>
Reviewed-by: Nicholas Husin <husin@google.com>
Auto-Submit: Gopher Robot <gobot@golang.org>
4 files changed
tree: 7a0a06a8985b19847ffe56a3c05bd8dcc8a9f0e1
  1. bpf/
  2. context/
  3. dict/
  4. dns/
  5. html/
  6. http/
  7. http2/
  8. http3/
  9. icmp/
  10. idna/
  11. internal/
  12. ipv4/
  13. ipv6/
  14. lif/
  15. nettest/
  16. netutil/
  17. proxy/
  18. publicsuffix/
  19. quic/
  20. route/
  21. trace/
  22. webdav/
  23. websocket/
  24. xsrftoken/
  25. .gitattributes
  26. .gitignore
  27. codereview.cfg
  28. CONTRIBUTING.md
  29. go.mod
  30. go.sum
  31. LICENSE
  32. PATENTS
  33. README.md
README.md

Go Networking

Go Reference

This repository holds supplementary Go networking packages.

Report Issues / Send Patches

This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.

The git repository is https://go.googlesource.com/net.

The main issue tracker for the net repository is located at https://go.dev/issues. Prefix your issue with “x/net:” in the subject line, so it is easy to find.