Template Escaping Flaw in Go's HTML Package Affects Trusted Template Authors
CVE-2026-97030
Currently unrated
What is CVE-2026-97030?
A flaw exists in the HTML package where the 'yield' keyword used in templates may not have been correctly escaped. This vulnerability affects trusted template authors, as it allows for potential exploitation if valid keyword usages are not properly handled. The current fix ensures that valid uses of the 'yield' keyword are escaped correctly, while non-keyword uses remain unaffected, enhancing the overall security of template rendering in Go applications.
Affected Version(s)
html/template 0 < 1.26.9
html/template 1.27.0-0 < 1.27.2
