Injection Vulnerability in Go Programming Language by Google
CVE-2026-56858

6.1MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-56858?

A vulnerability in Google’s Go programming language allows an attacker to exploit unescaped input parameters, leading to the early closure of a path with the '/' character. This flaw may permit the injection of malicious data, which could render the application susceptible to cross-site scripting (XSS) attacks. It is essential for developers using affected versions to implement necessary security measures to mitigate potential exploitation.

Affected Version(s)

html/template 0 < 1.25.13

html/template 1.26.0-0 < 1.26.6

html/template 1.27.0-0 < 1.27.0-rc.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Sherif
.