CVE-2026-94448: Reset context tracking on consecutive template expressions in html/template
Published Oct 8, 2026
·Updated
When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.
Affected Software
1 affected component
Google Go html/template
Event History
Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Frequently Asked Questions
1
How can I identify templates that may be affected?
Review html/template output that includes JavaScript template literals with consecutive expressions and subsequent regular expression literals. Those constructs are the conditions described for incorrect context tracking and escaping.