Skip to content

[pull] master from golang:master - #168

Merged
pull[bot] merged 1 commit into
trailofbits:masterfrom
golang:master
Aug 5, 2026
Merged

[pull] master from golang:master#168
pull[bot] merged 1 commit into
trailofbits:masterfrom
golang:master

Conversation

@pull

@pull pull Bot commented Aug 5, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

This change prevents pathological inputs from
closing an unescaped `/` early, allowing for
attacker-controlled data to inject arbitrary
unscaped content.

Additionally, CL 532595 hints at the invariant
in TestEscapeText potentially getting the update
this change makes.

For #80435
Fixes CVE-2026-56858

Change-Id: I502b8960249fa9a2827b44b64d081d224ac57cbc
Reviewed-on: https://go-review.googlesource.com/c/go/+/807100
Reviewed-by: Neal Patel <nealpatel@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
@pull pull Bot locked and limited conversation to collaborators Aug 5, 2026
@pull pull Bot added the ⤵️ pull label Aug 5, 2026
@pull
pull Bot merged commit de76efe into trailofbits:master Aug 5, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant