Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree
Details
CVE-2026-42502 affects multiple packages. Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. See references for individual vulnerability details.