CVE-2026-56858 PUBLISHED

Fix Javascript regexp context tracking in html/template

Assigner: Go
Reserved: 23.06.2026 Published: 13.08.2026 Updated: 14.08.2026

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Product Status

Vendor Go standard library
Product html/template
Versions Default: unaffected
  • affected from 0 to 1.25.13 (excl.)
  • affected from 1.26.0-0 to 1.26.6 (excl.)
  • affected from 1.27.0-0 to 1.27.0-rc.3 (excl.)

Credits

  • Ali Sherif

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')