Junglewise Threat Intelligence

CVE-2026-32289: Go html/template XSS in JS template literals

CVE-2026-32289 · Severity: medium · CVSS 6.1 · Published 2026-04-08

Technologies: stdlib (Go). Vendors: Google, Go.

Executive brief

A vulnerability exists in the Go programming language's standard library for generating web content. The library fails to correctly handle security protections when using certain JavaScript features in web templates, which could allow an attacker to inject malicious scripts into a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive information like session cookies.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Go 'html/template' package due to flawed context tracking within JavaScript template literals. Specifically, the template engine fails to properly track context across template branches and does not correctly maintain brace depth for template actions within these literals. This leads to incorrect or insufficient escaping of dynamic content. An attacker can exploit this by providing malicious input that, when rendered through an affected template, executes arbitrary JavaScript in the context of the victim's session. The issue is fixed in Go versions 1.25.9 and 1.26.2.

Affected products

  • Go standard library html/template < 1.25.9, >= 1.26.0-0 < 1.26.2

Timeline

  • 2026-03-24: disclosed: Issue opened in Go project repository
  • 2026-04-07: advisory: NVD and Go Project published advisory

References

Related threats