JavaScript Template Literal Context Tracking Vulnerability in Go
CVE-2026-94448
Currently unrated
What is CVE-2026-94448?
This vulnerability arises when a JavaScript template literal contains consecutive expressions. The context tracking state is not properly reset when entering a new expression, which leads to misrecognition of regular expression literals. This could allow incorrect parsing and handling of input within the application, potentially leading to application-level issues. Proper resets of context variables upon new expression entries are crucial to ensuring accurate recognition and escaping of subsequent literals.
Affected Version(s)
html/template 0 < 1.26.9
html/template 1.27.0-0 < 1.27.2
