PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97030 Go standard library CVE debrief

The Go standard library's html/template package did not correctly escape the 'yield' keyword, potentially allowing for template injection attacks. This has been addressed in versions 1.26.9 and 1.27.2. A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped. The vulnerability affects versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1.

Vendor
Go standard library
Product
stdlib
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Go applications, particularly those using the standard library's html/template package, should assess exposure and apply patches as needed. This includes reviewing and updating templates to ensure proper escaping of the 'yield' keyword and monitoring for any further updates or advisories from the Go project.

Why it matters

Defenders should prioritize verifying and applying patches for the Go standard library to prevent potential template injection attacks. The vulnerability affects versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1, and patches are available in versions 1.26.9 and 1.27.2. Evidence is limited, and further verification is recommended.

  • Potential for template injection attacks if not properly patched.
  • Need for verification and application of patches for affected versions.
  • Importance of reviewing and updating templates to ensure proper escaping of the 'yield' keyword.

Technical summary

The Go standard library's html/template package did not correctly escape the 'yield' keyword, potentially allowing for template injection attacks. This has been addressed in versions 1.26.9 and 1.27.2. The vulnerability affects versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1. Defenders should prioritize verifying and applying patches for the Go standard library to prevent potential template injection attacks. The fix involves ensuring proper escaping of the 'yield' keyword in templates without introducing security risks.

Defensive priority

Defenders should prioritize verifying and applying patches for the Go standard library, particularly for versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1.

Recommended defensive actions

  • Verify and apply patches for the Go standard library, particularly for versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1.
  • Review and update templates to ensure proper escaping of the 'yield' keyword.
  • Monitor for any further updates or advisories from the Go project.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide limited information about the vulnerability, with the primary details coming from the Go issue tracker and advisory. Evidence is limited, and further verification is recommended. The fix involves ensuring proper escaping of the 'yield' keyword in templates. Defenders should verify and apply patches for the Go standard library, particularly for versions 1.26.0 to 1.26.8 and 1.27.0-0 to 1.27.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97030 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97030

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97030 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97030

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.