CVE-2026-73505: Go Regex Replace By String Matchcve-2026-73505-go-regex-replace-by-string-match
Performing string replacement with `strings.Replace` or `strings.ReplaceAll` using a substring match returned from regex search on `$INPUT` replaces the first value match in `$INPUT` rather than at the regex match index. If the matched substring occurs earlier in `$INPUT`, the wrong substring will be replaced. Use index offsets (e.g., `FindStringMatchIndex`)