Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32289

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

A flaw was found in the html/template package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be incorrectly or improperly escaped, leading to Cross-Site Scripting (XSS) vulnerabilities. This could allow an attacker to inject malicious scripts into web pages viewed by other users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2redhat-user-workloads/applianceFix deferred
Builds for Red Hat OpenShiftredhat-user-workloads/openshift-builds-waiter-1-6Fix deferred
Builds for Red Hat OpenShiftredhat-user-workloads/openshift-builds-waiter-1-7Fix deferred
cert-manager Operator for Red Hat OpenShiftredhat-user-workloads/jetstack-cert-manager-1-17Fix deferred
cert-manager Operator for Red Hat OpenShiftredhat-user-workloads/jetstack-cert-manager-1-18Fix deferred
Compliance Operatorredhat-user-workloads/compliance-operator-bundle-releaseFix deferred
Confidential Compute Attestationredhat-user-workloads/osc-caaFix deferred
Confidential Compute Attestationredhat-user-workloads/trustee-operatorFix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftredhat-user-workloads/keda-adapterFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2456334html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals

EPSS

Процентиль: 21%
0.0029
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

CVSS3: 6.1
nvd
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

msrc
4 месяца назад

JsBraceDepth Context Tracking Bugs (XSS) in html/template

CVSS3: 6.1
debian
4 месяца назад

Context was not properly tracked across template branches for JS templ ...

CVSS3: 6.1
github
4 месяца назад

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

EPSS

Процентиль: 21%
0.0029
Низкий

5.4 Medium

CVSS3