CVE-2026-32289
Go 취약성 분석 및 완화

개요

CVE-2026-32289 is a Cross-Site Scripting (XSS) vulnerability in Go's html/template standard library package, caused by improper context tracking and brace depth handling within JavaScript template literals. Context was not properly tracked across template branches, and template actions within JS template literals did not properly track brace depth, leading to incorrect or missing escaping of content. Affected versions are Go 1.25.x before 1.25.9 and Go 1.26.0 before 1.26.2. It was published on April 8, 2026, with a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Feedly).

기술적 세부 사항

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). Two distinct flaws exist in Go's html/template package: (1) template context state is not correctly propagated across conditional branches when rendering JS template literals, and (2) template actions inside JS template literals fail to track curly-brace depth, causing the template engine to apply incorrect escaping rules. An attacker who can influence data rendered inside a JS template literal in an affected Go web application can inject unescaped JavaScript, triggering XSS in the victim's browser. No authentication is required on the attacker's side, but user interaction (visiting a crafted or compromised page) is needed (GitHub Advisory, Go Vuln DB).

영향

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the user. The scope is changed (S:C), meaning the impact extends beyond the vulnerable component to the user's browser environment. Confidentiality and integrity are both assessed as low impact, with no availability impact; however, chained with social engineering or persistent injection, the practical risk to user data and sessions can be significant (GitHub Advisory, Feedly).

착취 단계

  1. Identify a target application: Find a Go web application that uses the html/template package (versions before 1.25.9 or 1.26.2) and renders user-controlled data inside JavaScript template literals (backtick strings) within HTML templates.
  2. Craft a malicious payload: Prepare input that exploits the incorrect brace-depth or branch-context tracking — for example, input containing JS template literal syntax (e.g., ${...}) or conditional branch content that causes the template engine to skip or misapply escaping.
  3. Deliver the payload: Submit the crafted input through any user-controlled field (form input, URL parameter, API request body) that is subsequently rendered by the vulnerable template into a JS template literal context.
  4. Trigger victim execution: Induce a victim user to visit the page rendering the injected content (e.g., via phishing link or stored XSS in a shared resource), causing the unescaped JavaScript to execute in their browser.
  5. Achieve objective: The executed script can steal session cookies, perform actions on behalf of the user, exfiltrate sensitive page data, or redirect the user to a malicious site (GitHub Advisory, Go Vuln DB).

타협의 징후

  • Logs: Web server access logs showing requests with payloads containing JS template literal syntax (e.g., ${, backtick characters, or encoded equivalents) in user-supplied parameters rendered by Go html/template.
  • Network: Unexpected outbound requests from victim browsers to attacker-controlled domains following interaction with affected pages; unusual JavaScript-initiated HTTP requests in browser network logs.
  • Application Behavior: Unexpected JavaScript execution or error messages in browser consoles related to template rendering; reports from users of unexpected redirects or pop-ups on Go-based web applications.
  • File System: If the XSS is stored, look for persisted malicious payloads containing ${...} or backtick-delimited strings in application databases or user-generated content stores.

완화 및 해결 방법

Upgrade Go to version 1.25.9 (for the 1.25.x branch) or 1.26.2 (for the 1.26.x branch) to receive the fix (Go Vuln DB, Go CL). Organizations should audit all Go applications using html/template that render user-controlled data within JavaScript template literals and prioritize upgrading the Go toolchain. As a temporary workaround, avoid rendering untrusted user input directly inside JS template literals in Go templates until the patch is applied. Downstream distributions (openSUSE, Amazon Linux 2, Amazon Linux 2023) have also released updated packages incorporating the fix (openSUSE Advisory).

커뮤니티 반응

The Go team announced the vulnerability via the golang-announce mailing list and published a fix through the official Go change list (golang-announce). The vulnerability was discussed on oss-security mailing lists and picked up by Linux security news outlets covering the openSUSE and SUSE package updates (oss-sec). Downstream projects such as Portainer, oauth2-proxy, rclone, and CoreDNS have issued updated releases incorporating the patched Go version. Social media activity on Bluesky and Mastodon was limited, reflecting the moderate severity and lack of active exploitation.

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 Go 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2023-54365HIGH8.7
  • Go logoGo
  • kubeflow-katib
아니요Jun 23, 2026
CVE-2026-39822HIGH7.8
  • Go logoGo
  • cluster-api-provider-vsphere-fips-1.14
아니요Jul 08, 2026
CVE-2026-42504HIGH7.5
  • Go logoGo
  • flux-cli-2.8
아니요Jun 02, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • eks-distro-1.34
아니요Jul 08, 2026
CVE-2026-42507MEDIUM5.3
  • Go logoGo
  • apm-server-8.19
아니요Jun 02, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자