Vulnerability GO-2026-5970
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 14, 2026 at 05:29 PM UTC
Infinite loop on invalid input in golang.org/x/text
v0.1.0 - v0.38.0
v0.1.0 - v0.38.0
Summary
Infinite loop on invalid input in golang.org/x/text
Details
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
7 hours ago
Panic parsing crafted input in x/text/secure/precis in golang.org/x/text
v0.1.0 - v0.40.0 GO-2026-6629
v0.1.0 - v0.40.0 GO-2026-6629
High Risk
3 years ago
golang.org/x/text/language Out-of-bounds Read vulnerability
v0.1.0 - v0.3.6 GHSA-ppp9-7jff-5vj2
v0.1.0 - v0.3.6 GHSA-ppp9-7jff-5vj2
High Risk
3 years ago
golang.org/x/text/language Denial of service via crafted Accept-Language header
v0.1.0 - v0.3.7 GHSA-69ch-w2m2-3vjp
v0.1.0 - v0.3.7 GHSA-69ch-w2m2-3vjp
Unknown
3 years ago
Denial of service via crafted Accept-Language header in golang.org/x/text/language
v0.1.0 - v0.3.7 GO-2022-1059
v0.1.0 - v0.3.7 GO-2022-1059
Unknown
5 years ago
Out-of-bounds read in golang.org/x/text/language
v0.1.0 - v0.3.6 GO-2021-0113
v0.1.0 - v0.3.6 GO-2021-0113
Impacted packages
Timeline
Published
2 months ago
July 14, 2026 at 05:29 PM UTC
Last Modified
14 days ago
September 23, 2026 at 10:41 AM UTC