CVE Database
/

CVE-2023-29400

Back to search

CVE-2023-29400

Published: May 11, 2023

Modified: Jan 24, 2025

PUBLISHED

Description

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

VendorProductVersions

Go standard library

html/template

affected
0 - < 1.19.9
affected
1.20.0-0 - < 1.20.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now