
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-97030 is a template escaping bypass vulnerability in the Go standard library's html/template package, where the yield keyword is not correctly escaped in certain valid templates authored by trusted users. This can lead to improper injection of unintended content into rendered HTML output. The vulnerability affects Go versions prior to 1.26.9 and versions 1.27.0-0 through 1.27.2 (exclusive). It was published on October 8, 2026, with a patch released the same day. The CVSS base score has not been formally assigned, but Feedly estimates the severity as High (GitHub Advisory).
The root cause lies in the html/template package's failure to correctly escape the yield keyword when it appears in template code written by trusted authors. Specifically, valid uses of yield as a keyword were not being escaped, while non-keyword uses were also handled incorrectly, creating a discrepancy that could allow injection of unintended content. The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting) based on third-party classification (Radar Offseq). The fix, tracked as Go issue #81823 and change list CL/840925, ensures valid keyword uses are properly escaped and non-keyword uses are not (GitHub Advisory, Go Issue).
A trusted template author who can write or modify Go html/template templates could exploit this vulnerability to inject unintended content into rendered web pages, potentially enabling cross-site scripting (XSS) attacks against end users. The impact is limited to scenarios where a trusted (but potentially malicious or compromised) author has write access to templates, reducing the attack surface compared to fully unauthenticated vulnerabilities. Successful exploitation could result in session hijacking, credential theft, or delivery of malicious payloads to users of applications rendering the affected templates (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be a trusted template author with write access to templates, significantly limiting the exploitable population.
Upgrade Go to version 1.26.9 or later for the 1.26.x branch, or to 1.27.2 or later for the 1.27.x branch. No configuration-based workaround is available; patching is the recommended remediation. Additionally, organizations should review existing templates containing the yield keyword to ensure they do not rely on the previous (incorrect) escaping behavior, as the fix changes how yield is handled (GitHub Advisory, Go Vuln DB).
The Go team announced the fix via the golang-announce mailing list (golang-announce). The vulnerability was also disclosed on the oss-security mailing list shortly after publication (oss-sec). No significant broader media coverage or notable researcher commentary has been identified beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."