CVE-2026-56858

CVE-2026-56858: Fix Javascript regexp context tracking in html/template

Vendor Go Standard Library
Product html/template
Published August 13, 2026
Last update August 14, 2026

CVSS base score

What the vulnerability does

01Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 14, 2026 Record updated