CVE-2026-97030: 
cAdvisor vulnerability analysis and mitigation

Overview

CVE-2026-97030 is a template escaping bypass vulnerability in the Go standard library's html/template package, where the yield keyword is not correctly escaped in certain valid templates authored by trusted users. This can lead to improper injection of unintended content into rendered HTML output. The vulnerability affects Go versions prior to 1.26.9 and versions 1.27.0-0 through 1.27.2 (exclusive). It was published on October 8, 2026, with a patch released the same day. The CVSS base score has not been formally assigned, but Feedly estimates the severity as High (GitHub Advisory).

Technical details

The root cause lies in the html/template package's failure to correctly escape the yield keyword when it appears in template code written by trusted authors. Specifically, valid uses of yield as a keyword were not being escaped, while non-keyword uses were also handled incorrectly, creating a discrepancy that could allow injection of unintended content. The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting) based on third-party classification (Radar Offseq). The fix, tracked as Go issue #81823 and change list CL/840925, ensures valid keyword uses are properly escaped and non-keyword uses are not (GitHub Advisory, Go Issue).

Impact

A trusted template author who can write or modify Go html/template templates could exploit this vulnerability to inject unintended content into rendered web pages, potentially enabling cross-site scripting (XSS) attacks against end users. The impact is limited to scenarios where a trusted (but potentially malicious or compromised) author has write access to templates, reducing the attack surface compared to fully unauthenticated vulnerabilities. Successful exploitation could result in session hijacking, credential theft, or delivery of malicious payloads to users of applications rendering the affected templates (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to be a trusted template author with write access to templates, significantly limiting the exploitable population.

Mitigation and workarounds

Upgrade Go to version 1.26.9 or later for the 1.26.x branch, or to 1.27.2 or later for the 1.27.x branch. No configuration-based workaround is available; patching is the recommended remediation. Additionally, organizations should review existing templates containing the yield keyword to ensure they do not rely on the previous (incorrect) escaping behavior, as the fix changes how yield is handled (GitHub Advisory, Go Vuln DB).

Community reactions

The Go team announced the fix via the golang-announce mailing list (golang-announce). The vulnerability was also disclosed on the oss-security mailing list shortly after publication (oss-sec). No significant broader media coverage or notable researcher commentary has been identified beyond standard vulnerability tracking and aggregation sites.

Additional resources


Source: This report was generated using AI

Related cAdvisor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97031HIGH7.5
  • cAdvisor logocAdvisor
  • prometheus-statsd-exporter-fips-0.22
NoYesOct 08, 2026
CVE-2026-94440HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-elasticache-fips
NoYesOct 08, 2026
CVE-2026-94448MEDIUM6.1
  • cAdvisor logocAdvisor
  • longhorn-share-manager-fips-1.9
NoYesOct 08, 2026
CVE-2026-97032MEDIUM5.9
  • cAdvisor logocAdvisor
  • task
NoYesOct 08, 2026
CVE-2026-97030NONEN/A
  • cAdvisor logocAdvisor
  • cluster-api-1.14
NoYesOct 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management