CVE-2026-97030: Recognize yield as regexp preceder keyword in html/template
A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using Go's html/template package may be exposed if a trusted template author wrote a valid template that uses the yield keyword in a context where it should be treated as a regular-expression preceder. The issue is relevant where template output can include attacker-controlled content that relies on correct escaping.
What condition is needed for exploitation?
The affected template must contain a valid use of the yield keyword that was not correctly escaped by html/template. The available information does not identify a separate authentication, network, or configuration prerequisite.
What should teams check when assessing impact?
Review html/template templates for uses of yield, especially where the keyword precedes values influenced by untrusted input and the generated output uses regular-expression contexts. Confirm that the deployed Go version includes the change that recognizes valid yield keyword uses as regexp preceders.