CVE Database
/

CVE-2026-39826

Back to search

CVE-2026-39826

Published: May 7, 2026

Modified: May 8, 2026

PUBLISHED

Description

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

VendorProductVersions

Go standard library

html/template

affected
0 - < 1.25.10
affected
1.26.0-0 - < 1.26.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now