golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git-lfs | Aug 22, 2024 | Dec 26, 2022 |
| Debian | — | Upgrade golang-golang-x-text | Jul 30, 2024 | Dec 26, 2022 |
| Redhat Openshift | — | Upgrade openshiftUpgrade haproxyUpgrade kernel-rtUpgrade cri-o | Aug 21, 2023 | Aug 12, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 26, 2022 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.6Upgrade Splunk Enterprise to version 9.1.1Upgrade Splunk Enterprise to version 8.2.12 | Jul 30, 2026 | Dec 26, 2022 |
| Ubuntu | — | Upgrade golang-x-text-devUpgrade golang-golang-x-text-dev | Mar 22, 2023 | Dec 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub