JavaScript Template Literal Context Tracking Vulnerability in Go
CVE-2026-94448

Currently unrated

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-94448?

This vulnerability arises when a JavaScript template literal contains consecutive expressions. The context tracking state is not properly reset when entering a new expression, which leads to misrecognition of regular expression literals. This could allow incorrect parsing and handling of input within the application, potentially leading to application-level issues. Proper resets of context variables upon new expression entries are crucial to ensuring accurate recognition and escaping of subsequent literals.

Affected Version(s)

html/template 0 < 1.26.9

html/template 1.27.0-0 < 1.27.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.