Back

MEDIUM

JsBraceDepth Context Tracking Bugs (XSS) in html/template

Published Apr 8, 2026

Description

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Go
Published Apr 8, 2026
Updated Apr 13, 2026
Reserved Mar 11, 2026
CISA Vulnrichment
Updated Apr 13, 2026
NVD
Status Analyzed
Modified Jul 25, 2026
Red Hat
Severity Moderate
Public date Apr 8, 2026