« Volver al listado

CVE-2026-32289

Estado: AnalizadaMedia (6.1)—

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-32289",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-32289",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-13T17:48:22.714020Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "html/template",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.25.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.26.0-0",
              "lessThan": "1.26.2",
              "versionType": "semver"
            }
          ],
          "packageName": "html/template",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "context.String"
            },
            {
              "name": "context.mangle"
            },
            {
              "name": "escaper.escapeBranch"
            },
            {
              "name": "Error.Error"
            },
            {
              "name": "HTMLEscaper"
            },
            {
              "name": "JSEscape"
            },
            {
              "name": "JSEscapeString"
            },
            {
              "name": "JSEscaper"
            },
            {
              "name": "ParseFS"
            },
            {
              "name": "ParseFiles"
            },
            {
              "name": "ParseGlob"
            },
            {
              "name": "Template.AddParseTree"
            },
            {
              "name": "Template.Clone"
            },
            {
              "name": "Template.DefinedTemplates"
            },
            {
              "name": "Template.Execute"
            },
            {
              "name": "Template.ExecuteTemplate"
            },
            {
              "name": "Template.Funcs"
            },
            {
              "name": "Template.Parse"
            },
            {
              "name": "Template.ParseFS"
            },
            {
              "name": "Template.ParseFiles"
            },
            {
              "name": "Template.ParseGlob"
            },
            {
              "name": "URLQueryEscaper"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-08T02:16:03.820",
  "references": [
    {
      "url": "https://go.dev/cl/763762",
      "tags": [
        "Patch"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/78331",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2026-4865",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."
    },
    {
      "lang": "es",
      "value": "El contexto no se seguía correctamente a través de las ramas de la plantilla para los literales de plantilla de JS, lo que llevó a un escape posiblemente incorrecto del contenido cuando se usaban las ramas. Además, las acciones de la plantilla dentro de los literales de plantilla de JS no seguían correctamente la profundidad de las llaves, lo que llevó a que se aplicara un escape incorrecto. Estos problemas podrían causar que las acciones dentro de los literales de plantilla de JS fueran escapadas incorrecta o indebidamente, lo que llevó a vulnerabilidades de XSS."
    }
  ],
  "lastModified": "2026-07-25T10:10:00.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6C9C072-9817-402D-877F-F83584B07017",
              "versionEndExcluding": "1.25.9"
            },
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39FE9BAF-55E9-43AA-B14E-239E7EF1D65D",
              "versionEndExcluding": "1.26.2",
              "versionStartIncluding": "1.26.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@golang.org"
}