CVE-2026-94448 PUBLISHED

Reset context tracking on consecutive template expressions in html/template

Assigner: Go
Reserved: 21.09.2026 Published: 08.10.2026 Updated: 08.10.2026

When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.

Product Status

Vendor Go standard library
Product html/template
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')