CVE-2026-32289General(golang / go)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-08: 204-0804-1704-18
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure1General2
2026-04-171
General1
2026-04-181
Patch1
Full discourse5 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-32289 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/462 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    CVE-2026-32289 has been removed from AWS Lambda base images, indicating that a patch or hotfix has addressed the issue; no exploits or PoC details are discussed.

    0000046
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-32289 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/462 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The message reports that CVE‑2026‑32289 is no longer present in the latest AWS Lambda base images, but provides no additional technical, exploit, or patch information.

    0000023
    34 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-32289 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/462 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new, unclassified CVE (CVE‑2026‑32289) has been identified in AWS Lambda’s standard library across 26 base images, but no exploit proof, tool, or patch information is provided.

    0000046
    31 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32289 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32289 #CVE-2026-32289 #CVE #CyberSecurity #InfoSec https://t.co/1OISl7190M

    Post summary

    The tweet simply lists the CVE reference with no further technical or operational information.

    0000042
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32289 Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additio… https://www.cve.org/CVERecord?id=CVE-2026-32289

    Post summary

    The text outlines a discovered bug involving improper context tracking with JavaScript template literals, but provides no evidence of exploits, patches, or active use.

    00000104
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more