The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Golang
Subscribe
|
Text
Subscribe
|
|
Redhat
Subscribe
|
3scale Amp
Subscribe
Acm
Subscribe
Container Native Virtualization
Subscribe
Devtools
Subscribe
Enterprise Linux
Subscribe
Integration
Subscribe
Jaeger
Subscribe
Jboss Fuse
Subscribe
Openshift
Subscribe
Openshift Container Storage
Subscribe
Quay
Subscribe
Rhel Extras Other
Subscribe
Serverless
Subscribe
Service Mesh
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0962 | The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. |
Github GHSA |
GHSA-5rcv-m4m3-hfh7 | golang.org/x/text Infinite loop |
Ubuntu USN |
USN-5873-1 | Go Text vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el7 |
Mon, 19 Aug 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el8 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.681Z
Reserved: 2020-06-12T00:00:00
Link: CVE-2020-14040
No data.
Status : Modified
Published: 2020-06-17T20:15:09.993
Modified: 2024-11-21T05:02:25.223
Link: CVE-2020-14040
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN