Metrics
Affected Vendors & Products
Thu, 16 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang go |
|
| CPEs | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Golang
Golang go |
Mon, 13 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 |
Thu, 09 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-116 CWE-79 |
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go Standard Library
Go Standard Library html/template |
|
| Vendors & Products |
Go Standard Library
Go Standard Library html/template |
Wed, 08 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities. | |
| Title | JsBraceDepth Context Tracking Bugs (XSS) in html/template | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published: 2026-04-08T01:06:56.297Z
Updated: 2026-04-13T18:20:46.377Z
Reserved: 2026-03-11T16:38:46.557Z
Link: CVE-2026-32289
Updated: 2026-04-13T17:48:19.317Z
Status : Analyzed
Published: 2026-04-08T02:16:03.820
Modified: 2026-04-16T19:06:57.367
Link: CVE-2026-32289