Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".
Advisories
Source ID Title
EUVD EUVD EUVD-2025-31408 github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Github GHSA Github GHSA GHSA-fmjh-f678-cv3x github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Textit
Textit phonenumbers
CPEs cpe:2.3:a:textit:phonenumbers:*:*:*:*:*:*:*:*
Vendors & Products Textit
Textit phonenumbers

Mon, 29 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Phonenumbers Project
Phonenumbers Project phonenumbers
Vendors & Products Phonenumbers Project
Phonenumbers Project phonenumbers

Sat, 27 Sep 2025 05:15:00 +0000

Type Values Removed Values Added
Description Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".
Weaknesses CWE-1286
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2025-09-29T13:42:17.769Z

Reserved: 2025-09-25T07:30:18.158Z

Link: CVE-2025-10954

cve-icon Vulnrichment

Updated: 2025-09-29T13:41:13.247Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-27T05:15:29.803

Modified: 2025-10-03T18:30:04.820

Link: CVE-2025-10954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-29T09:29:47Z