Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32289

Опубликовано: 08 апр. 2026
Источник: debian
EPSS Низкий

Описание

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25fixed1.25.9-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78331

  • Fixed by: https://github.com/golang/go/commit/babb1c32c2e7ee7a1147e7e587d35c553fb693ad (go1.26.2)

  • Fixed by: https://github.com/golang/go/commit/3ed316924408a02b256544eb40607e73702f2d0c (go1.25.9)

EPSS

Процентиль: 21%
0.0029
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

CVSS3: 5.4
redhat
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

CVSS3: 6.1
nvd
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

msrc
4 месяца назад

JsBraceDepth Context Tracking Bugs (XSS) in html/template

CVSS3: 6.1
github
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

EPSS

Процентиль: 21%
0.0029
Низкий