CVE-2026-97030 PUBLISHED

Recognize yield as regexp preceder keyword in html/template

Assigner: Go
Reserved: 23.09.2026 Published: 08.10.2026 Updated: 08.10.2026

A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.

Product Status

Vendor Go standard library
Product html/template
Versions Default: unaffected
  • affected from 0 to 1.26.9 (excl.)
  • affected from 1.27.0-0 to 1.27.2 (excl.)

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')