Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:golang/github.com/golang/go/src/html/template

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Join the discussion

CVE-2026-39826 is a medium severity cross-site scripting (XSS) vulnerability in the Go standard library's html/template package. It occurs when a trusted template author includes a <script> tag with an empty or whitespace-only 'type' attribute, leading to improper escaping of data inside the script block. This can allow injection of malicious scripts if untrusted data is passed into the template. The vulnerability affects Go versions up to and including 1.26.0-0. There is no official patch or remediation guidance available, and no known exploits have been reported in the wild.

Join the discussion

CVE-2026-39823 is a medium severity cross-site scripting (XSS) vulnerability in the Go standard library's html/template package. The issue arises from improper escaping of URLs within a <meta> tag's content attribute when ASCII whitespaces surround the '=' character, which allows partial bypass of escaping. This affects Go versions up to 1.26.0-0. No official patch or remediation guidance has been confirmed by the vendor, and no known exploits exist in the wild at this time.

Join the discussion

CVE-2026-32289 is a medium severity cross-site scripting (XSS) vulnerability in the Go standard library's html/template package. It arises from improper escaping of content within JavaScript template literals due to incorrect context tracking and brace depth handling. This flaw can lead to XSS when template branches are used. The vulnerability affects Go versions up to and including 1.26.0-0. No official patch or remediation guidance is currently available, and no known exploits have been reported in the wild.

Join the discussion

CVE-2026-27142 is a medium severity cross-site scripting (XSS) vulnerability in the Go standard library's html/template package. It occurs because URLs inserted into the content attribute of HTML meta tags are not properly escaped when the meta tag includes an http-equiv attribute with the value "refresh". This improper neutralization can allow an attacker to inject malicious scripts. A new GODEBUG setting, htmlmetacontenturlescape, has been introduced to control escaping behavior for URLs in meta content attributes. No official patch or fix details are provided in the available data.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:golang/github.com/golang/go/src/html/template
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses