GHSA-ppp9-7jff-5vj2

Source
https://github.com/advisories/GHSA-ppp9-7jff-5vj2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-ppp9-7jff-5vj2/GHSA-ppp9-7jff-5vj2.json
Aliases
Published
2022-12-26T06:30:22Z
Modified
2023-11-08T04:06:28.495390Z
Details

golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

References

Affected packages

Go / golang.org/x/text

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.3.7