CVE-2026-94448: Go Standard Library Html/template

EPSS: 0.2% chance of exploitation in the next 30 days.

When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.

Affected products

  • Go Standard Library Html/template: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)

Published 2026-10-08. Last modified 2026-10-09.