Vulnerability GO-2026-6091

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 09:43 PM UTC
Fix Javascript regexp context tracking in html/template
<1.25.13
<1.25.13

Summary

Fix Javascript regexp context tracking in html/template

Details

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Impacted packages

Timeline

Published
1 month ago
August 13, 2026 at 09:43 PM UTC
Last Modified
3 days ago
September 25, 2026 at 10:41 AM UTC