Description
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Potential template injection
Action: Apply Patch
AI Analysis

Impact

A template author who writes a template in Go's standard html/template package may create a mis‑interpreted ‘yield’ keyword if it is not escaped. The flawed logic fails to neutralize input correctly, corresponding to CWE‑74, and allows the template engine to interpret untrusted text as a template command. This can lead to unintended template execution or injection of malicious content into rendered output, representing a potential template injection vulnerability.

Affected Systems

The vulnerability is present in the Go standard library package html/template. No specific version ranges are listed in the advisory, so users should verify whether their installed Go release incorporates the fix referenced in the official issue tracker. Any version prior to the patch that allows an unescaped ‘yield’ token in trusted author templates is affected.

Risk and Exploitability

The CVE does not provide a CVSS or EPSS score, and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector requires an attacker to control or modify a trusted template that contains an unescaped ‘yield’ keyword, which could happen when developers unknowingly deploy such templates or when templates are retrieved from untrusted sources. Because the flaw is limited to trusted template authors, the likelihood of exploitation depends on the organization’s template management practices.

Generated by OpenCVE AI on October 9, 2026 at 01:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade your Go installation to a version that includes the fix referenced at https://go.dev/cl/840925
  • Audit all existing html/template files for unescaped use of the word ‘yield’ and escape or remove it if it is literal text
  • If an immediate upgrade is not possible, employ a temporary bypass by wrapping the literal word ‘yield’ in a no‑op placeholder or by redefining it in the template environment so it is not parsed as a keyword

Generated by OpenCVE AI on October 9, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74

Fri, 09 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Go Standard Library
Go Standard Library html/template
Vendors & Products Go Standard Library
Go Standard Library html/template

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Title Recognize yield as regexp preceder keyword in html/template
References

Subscriptions

Go Standard Library Html/template
cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:57.597Z

Reserved: 2026-09-23T23:03:01.995Z

Link: CVE-2026-97030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:05.910

Modified: 2026-10-08T23:17:05.910

Link: CVE-2026-97030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:30:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')