Go standard library html/template
5 known vulnerabilities in Go standard library html/template, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-56858 CVSS 6.1 medium Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content…
- CVE-2026-39826 CVSS 6.1 medium If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII…
- CVE-2026-39823 CVSS 6.1 medium CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL…
- CVE-2026-32289 CVSS 6.1 medium Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when…
- CVE-2026-27142 CVSS 6.1 medium Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an…