CVE-2026-97030: Go Standard Library Html/template

EPSS: 0.2% chance of exploitation in the next 30 days.

A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.

Affected products

  • Go Standard Library Html/template: before 1.26.9 (fixed in 1.26.9); from 1.27.0-0, before 1.27.2 (fixed in 1.27.2)

Published 2026-10-08. Last modified 2026-10-09.