Vulnerability Report: GO-2026-5970
- CVE-2026-56852
- Affects: golang.org/x/text
- Published: Jul 14, 2026
- Modified: Aug 10, 2026
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.39.0
22 affected symbols
- Form.Append
- Form.AppendString
- Form.Bytes
- Form.FirstBoundary
- Form.FirstBoundaryInString
- Form.IsNormal
- Form.IsNormalString
- Form.LastBoundary
- Form.NextBoundary
- Form.NextBoundaryInString
- Form.Properties
- Form.PropertiesString
- Form.QuickSpan
- Form.QuickSpanString
- Form.Span
- Form.SpanString
- Form.String
- Form.Transform
- Iter.Init
- Iter.InitString
- Iter.Next
- Iter.Seek
Aliases
References
Credits
- Viky Choi ("vikychoi" on GitHub)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.