golang.org/x/text/language Out-of-bounds Read vulnerability
High severity
GitHub Reviewed
Published
Dec 26, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Description
Published by the National Vulnerability Database
Dec 26, 2022
Published to the GitHub Advisory Database
Dec 26, 2022
Reviewed
Jan 9, 2023
Last updated
Oct 2, 2023
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
References