CVE-2023-24539: Golang Go
High severity, CVSS 7.3. EPSS: 1% chance of exploitation in the next 30 days.
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.
Affected products
- Golang Go: before 1.19.9 (fixed in 1.19.9); from 1.20.0, before 1.20.4 (fixed in 1.20.4)
Published 2023-05-11. Last modified 2026-06-17.