Repository navigation
html/template: JS template literal context incorrectly tracked #78331
Copy link
Copy link
Closed
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Milestone
Description
Activity
- addedBugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.
on Mar 24, 2026 - addedNeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.
on Mar 25, 2026 @gopherbot please open backport issues for this security fix
Backport issue(s) opened: #78416 (for 1.25), #78417 (for 1.26).
Remember to create the cherry-pick CL(s) as soon as the patch is submitted to master, according to https://go.dev/wiki/MinorReleases.
Change https://go.dev/cl/763543 mentions this issue:
[release-branch.go1.26] html/template: properly track JS template literal brace depth across contextsChange https://go.dev/cl/763551 mentions this issue:
[release-branch.go1.25] html/template: properly track JS template literal brace depth across contexts- added 2 commits that reference this issue
on Apr 7, 2026 - changed the title
[-]security: fix CVE-2026-32289[/-][+]html/template: JS template literal context incorrectly tracked[/+]on Apr 7, 2026 Change https://go.dev/cl/763762 mentions this issue:
html/template: properly track JS template literal brace depth across contexts- added a commit that references this issue
on Apr 8, 2026
Metadata
Metadata
Assignees
Labels
BugReportIssues describing a possible bug in the Go implementation.Issues describing a possible bug in the Go implementation.NeedsFixThe path to resolution is known, but the work has not been done.The path to resolution is known, but the work has not been done.Securityrelease-blocker
Context was not properly tracked across template branches for JS template
literals, leading to possibly incorrect escaping of content when branches were
used.
Additionally template actions within JS template literals did not properly track
the brace depth, leading to incorrect escaping being applied.
These issues could cause actions within JS template literals to be incorrectly
or improperly escaped, leading to XSS vulnerabilities.
This only affects templates that use template actions within JS template literals.
This is CVE-2026-32289 and Go issue https://go.dev/issue/78331.
This is a PRIVATE issue for CVE-2026-32289, tracked in http://b/491530416 and fixed by https://go-internal-review.git.corp.google.com/c/go/+/3882.
/cc @golang/security and @golang/release