CVE-2026-94448
Public on 2026-10-08
Modified on 2026-10-10
Description
When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.
We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81821
NOTE: Fixed by: https://github.com/golang/go/commit/b26d150e6985f804826f4fcb1aa33aa81e700b52 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/e59c03e695f2eaa26e308f756c83773afb034e47 (go1.26.9)
We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81821
NOTE: Fixed by: https://github.com/golang/go/commit/b26d150e6985f804826f4fcb1aa33aa81e700b52 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/e59c03e695f2eaa26e308f756c83773afb034e47 (go1.26.9)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2027 Preview | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | buildah | Pending Fix | ||
| Amazon Linux 2027 Preview | buildah | Pending Fix | ||
| Amazon Linux 2 - Core | cni-plugins | Pending Fix | ||
| Amazon Linux 2023 | cni-plugins | Pending Fix | ||
| Amazon Linux 2027 Preview | cni-plugins | Pending Fix | ||
| Amazon Linux 2 - Core | cri-tools | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | docker | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | docker | Pending Fix | ||
| Amazon Linux 2023 | docker | Pending Fix | ||
| Amazon Linux 2027 Preview | docker | Pending Fix | ||
| Amazon Linux 2023 | git-lfs | Pending Fix | ||
| Amazon Linux 2027 Preview | git-lfs | Pending Fix | ||
| Amazon Linux 2 - Core | golang | Pending Fix | ||
| Amazon Linux 2 - Golang1.11 Extra | golang | No Fix Planned | ||
| Amazon Linux 2 - Golang1.19 Extra | golang | No Fix Planned | ||
| Amazon Linux 2 - Golang1.9 Extra | golang | No Fix Planned | ||
| Amazon Linux 2023 | golang | Pending Fix | ||
| Amazon Linux 2027 Preview | golang | Pending Fix | ||
| Amazon Linux 2023 | libcap | Pending Fix | ||
| Amazon Linux 2027 Preview | libcap | Pending Fix | ||
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2 - Ecs Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2027 Preview | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | skopeo | Pending Fix | ||
| Amazon Linux 2027 Preview | skopeo | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2027 Preview | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | yq | Pending Fix | ||
| Amazon Linux 2027 Preview | yq | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |