Vulnerability GHSA-ppp9-7jff-5vj2
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
December 26, 2022 at 06:30 AM UTC
golang.org/x/text/language Out-of-bounds Read vulnerability
v0.1.0 - v0.3.6
v0.1.0 - v0.3.6
Summary
golang.org/x/text/language Out-of-bounds Read vulnerability
Details
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
7 hours ago
Panic parsing crafted input in x/text/secure/precis in golang.org/x/text
v0.1.0 - v0.40.0 GO-2026-6629
v0.1.0 - v0.40.0 GO-2026-6629
Unknown
2 months ago
Infinite loop on invalid input in golang.org/x/text
v0.1.0 - v0.38.0 GO-2026-5970
v0.1.0 - v0.38.0 GO-2026-5970
High Risk
3 years ago
golang.org/x/text/language Denial of service via crafted Accept-Language header
v0.1.0 - v0.3.7 GHSA-69ch-w2m2-3vjp
v0.1.0 - v0.3.7 GHSA-69ch-w2m2-3vjp
Unknown
3 years ago
Denial of service via crafted Accept-Language header in golang.org/x/text/language
v0.1.0 - v0.3.7 GO-2022-1059
v0.1.0 - v0.3.7 GO-2022-1059
Unknown
5 years ago
Out-of-bounds read in golang.org/x/text/language
v0.1.0 - v0.3.6 GO-2021-0113
v0.1.0 - v0.3.6 GO-2021-0113
Impacted packages
Timeline
Published
3 years ago
December 26, 2022 at 06:30 AM UTC
Last Modified
27 days ago
September 10, 2026 at 03:49 AM UTC