Description
When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting via incorrect template context resetting
Action: Update Go runtime
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability becomes exploitable when an attacker can supply a template containing consecutive expressions that are rendered by the Go html/template package. The missing reset of context tracking causes subsequent regular expression literals to be misidentified and inadequately escaped, allowing injection of malicious JavaScript into the rendered output. The result is a web‑application‑level injection that can lead to arbitrary code execution in a victim’s browser, compromising confidentiality and integrity.

Affected Systems

Affected systems are all Go standard library html/template users in versions of Go that precede the fix documented in the referenced Go issue trackers. The patch is available in newer releases of Go; any program that compiles with an affected Go version and renders user‑supplied templates is at risk.

Risk and Exploitability

Based on the description, it is inferred that attackers would need to supply a template containing a malicious JavaScript literal—an ability that can arise for template‑driven web applications or command‑line tools. The likely attack vector involves providing a template from an untrusted source that contains consecutive expressions. Once the template is processed, the incorrect escaping can be leveraged for XSS. Although an EPSS score is not available and the vulnerability is not listed in CISA KEV, the nature of the flaw indicates high impact. The lack of EPSS data does not diminish the severity of the flaw, as attackers already have a clear path to exploitation via compromised templates.

Generated by OpenCVE AI on October 9, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go release that contains the html/template fix
  • Audit template sources to ensure only trusted content is used in templates
  • If upgrade is not yet possible, replace dynamic template expressions with safe static strings or implement a custom wrapper that enforces proper escaping

Generated by OpenCVE AI on October 9, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 09 Oct 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library html/template
Vendors & Products Go Standard Library
Go Standard Library html/template

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.
Title Reset context tracking on consecutive template expressions in html/template
References

Subscriptions

Go Standard Library Html/template
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:57.417Z

Reserved: 2026-09-21T16:43:04.758Z

Link: CVE-2026-94448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:05.300

Modified: 2026-10-08T23:17:05.300

Link: CVE-2026-94448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T02:00:23Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')