Vulnerability GO-2026-6599

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 08, 2026 at 10:31 PM UTC
Reset context tracking on consecutive template expressions in html/template
<1.26.9
<1.26.9

Summary

Reset context tracking on consecutive template expressions in html/template

Details

When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.

We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.

Impacted packages

Timeline

Published
8 hours ago
October 08, 2026 at 10:31 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 11:00 PM UTC