MEDIUM5.3
GHSA-fmjh-f678-cv3x
github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Quick fix
GHSA-fmjh-f678-cv3x — github.com/nyaruka/phonenumbers: upgrade to the fixed version with the command below.
go get github.com/nyaruka/phonenumbers@v1.2.2Details
Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/nyaruka/phonenumbers
Introduced in:
0Fixed in: 1.2.2Fix
go get github.com/nyaruka/phonenumbers@v1.2.2References
- https://nvd.nist.gov/vuln/detail/CVE-2025-10954[ADVISORY]
- https://github.com/nyaruka/phonenumbers/issues/148[WEB]
- https://github.com/nyaruka/phonenumbers/commit/0479e35488e8a002a261cdb515ef8a7f80ca37fe[WEB]
- https://github.com/nyaruka/phonenumbers[PACKAGE]
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMNYARUKAPHONENUMBERS-6084070[WEB]