CVE-2026-97030
Public on 2026-10-08
Modified on 2026-10-10
Description
A trusted template author may have previously written a valid template wherein the use of the |yield| keyword would not be correctly escaped.
We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81823
NOTE: Fixed by: https://github.com/golang/go/commit/6e2cfab0a1c1683c52f9e09270627b0c4e6446e3 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/5d84f6f08caf63b5f1300930368756bd34955f4a (go1.26.9)
We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped.
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81823
NOTE: Fixed by: https://github.com/golang/go/commit/6e2cfab0a1c1683c52f9e09270627b0c4e6446e3 (go1.27.2)
NOTE: Fixed by: https://github.com/golang/go/commit/5d84f6f08caf63b5f1300930368756bd34955f4a (go1.26.9)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Docker Extra | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2027 Preview | amazon-ecr-credential-helper | Pending Fix | ||
| Amazon Linux 2023 | buildah | Pending Fix | ||
| Amazon Linux 2027 Preview | buildah | Pending Fix | ||
| Amazon Linux 2 - Core | cni-plugins | Pending Fix | ||
| Amazon Linux 2023 | cni-plugins | Pending Fix | ||
| Amazon Linux 2027 Preview | cni-plugins | Pending Fix | ||
| Amazon Linux 2 - Core | cri-tools | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | docker | Pending Fix | ||
| Amazon Linux 2023 | docker | Pending Fix | ||
| Amazon Linux 2027 Preview | docker | Pending Fix | ||
| Amazon Linux 2023 | git-lfs | Pending Fix | ||
| Amazon Linux 2027 Preview | git-lfs | Pending Fix | ||
| Amazon Linux 2 - Core | golang | Pending Fix | ||
| Amazon Linux 2 - Golang1.11 Extra | golang | No Fix Planned | ||
| Amazon Linux 2 - Golang1.19 Extra | golang | No Fix Planned | ||
| Amazon Linux 2 - Golang1.9 Extra | golang | No Fix Planned | ||
| Amazon Linux 2023 | golang | Pending Fix | ||
| Amazon Linux 2027 Preview | golang | Pending Fix | ||
| Amazon Linux 2023 | libcap | Pending Fix | ||
| Amazon Linux 2027 Preview | libcap | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2027 Preview | oci-add-hooks | Pending Fix | ||
| Amazon Linux 2023 | skopeo | Pending Fix | ||
| Amazon Linux 2027 Preview | skopeo | Pending Fix | ||
| Amazon Linux 2 - Docker Extra | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2027 Preview | soci-snapshotter | Pending Fix | ||
| Amazon Linux 2023 | yq | Pending Fix | ||
| Amazon Linux 2027 Preview | yq | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |