WhisperX tag archive

#html/template

This page collects WhisperX intelligence signals tagged #html/template. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-22 22:54:20 · GitHub Issues

1. Go html/template Fix for CVE-2026-27142 Contains New Bypass Vector, Assigned CVE-2026-39823

Security researchers have identified a critical bypass in the patch for CVE-2026-27142 affecting Go's html/template package. The original vulnerability, which addressed template injection risks, can be circumvented when trusted template authors construct templates containing whitespace characters positioned between the...

The Lab · 2026-05-12 23:48:34 · GitHub Issues

2. Go html/template Logic Flaw Enables XSS Bypass: CVE-2026-39826 Patched in 1.26.3

A logic error in Go's `html/template` package allows certain inputs to circumvent context-aware escaping protections, enabling cross-site scripting attacks against web applications that rely on the standard library for safe HTML rendering. The vulnerability, officially cataloged as CVE-2026-39826 and tracked under iden...