VDB
Sign up
HIGH7.5

GHSA-ppp9-7jff-5vj2

golang.org/x/text/language Out-of-bounds Read vulnerability

Quick fix

GHSA-ppp9-7jff-5vj2 — golang.org/x/text: upgrade to the fixed version with the command below.

go get golang.org/x/text@v0.3.7

Details

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/text
Introduced in: 0Fixed in: 0.3.7
Fixgo get golang.org/x/text@v0.3.7

References