CVE-2026-32289

EUVD-2026-20018
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
golang-1.19
bookworm
vulnerable
golang-1.24
forky
vulnerable
sid
vulnerable
trixie
vulnerable
golang-1.25
forky
vulnerable
sid
1.25.9-1
fixed
golang-1.26
forky
vulnerable
sid
1.26.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
questing
dne
golang-1.6
jammy
dne
noble
dne
questing
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
xenial
needs-triage
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
questing
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
golang-1.17
jammy
needs-triage
noble
dne
questing
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
xenial
needs-triage
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
questing
needs-triage
golang-1.24
jammy
needs-triage
noble
needs-triage
questing
needs-triage
golang-1.25
jammy
dne
noble
dne
questing
needs-triage