CVE-2026-97030: Recognize yield as regexp preceder keyword in html/template

Published Oct 8, 2026
·
Updated

A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.

Affected Software

1 affected component
Google Go

Event History

Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using Go's html/template package may be exposed if a trusted template author wrote a valid template that uses the yield keyword in a context where it should be treated as a regular-expression preceder. The issue is relevant where template output can include attacker-controlled content that relies on correct escaping.

2

What condition is needed for exploitation?

The affected template must contain a valid use of the yield keyword that was not correctly escaped by html/template. The available information does not identify a separate authentication, network, or configuration prerequisite.

3

What should teams check when assessing impact?

Review html/template templates for uses of yield, especially where the keyword precedes values influenced by untrusted input and the generated output uses regular-expression contexts. Confirm that the deployed Go version includes the change that recognizes valid yield keyword uses as regexp preceders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203