Skip to content

html/template: JS template literal context incorrectly tracked #78331

Description

@neild

Context was not properly tracked across template branches for JS template
literals, leading to possibly incorrect escaping of content when branches were
used.
 
Additionally template actions within JS template literals did not properly track
the brace depth, leading to incorrect escaping being applied.
 
These issues could cause actions within JS template literals to be incorrectly
or improperly escaped, leading to XSS vulnerabilities.
 
This only affects templates that use template actions within JS template literals.
 
 
This is CVE-2026-32289 and Go issue https://go.dev/issue/78331.


This is a PRIVATE issue for CVE-2026-32289, tracked in http://b/491530416 and fixed by https://go-internal-review.git.corp.google.com/c/go/+/3882.

/cc @golang/security and @golang/release

Activity

  1. added this to the Go1.27 milestone on Mar 24, 2026
  2. added
    BugReportIssues describing a possible bug in the Go implementation.
    on Mar 24, 2026
  3. added
    NeedsFixThe path to resolution is known, but the work has not been done.
    on Mar 25, 2026
  4. neild commented on Mar 27, 2026

    @neild
    ContributorAuthor

    @gopherbot please open backport issues for this security fix

  5. gopherbot commented on Mar 27, 2026

    @gopherbot
    Contributor

    Backport issue(s) opened: #78416 (for 1.25), #78417 (for 1.26).

    Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.

  6. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763543 mentions this issue: [release-branch.go1.26] html/template: properly track JS template literal brace depth across contexts

  7. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763551 mentions this issue: [release-branch.go1.25] html/template: properly track JS template literal brace depth across contexts

  8. added 2 commits that reference this issue on Apr 7, 2026
    3ed3169
    babb1c3
  9. changed the title [-]security: fix CVE-2026-32289[/-] [+]html/template: JS template literal context incorrectly tracked[/+] on Apr 7, 2026
  10. gopherbot commented on Apr 7, 2026

    @gopherbot
    Contributor

    Change https://go.dev/cl/763762 mentions this issue: html/template: properly track JS template literal brace depth across contexts

  11. added a commit that references this issue on Apr 8, 2026
    199c4d1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugReportIssues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.Securityrelease-blocker

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions