Impact
The Nickname profile in golang.org/x/text/secure/precis contains an out-of-bounds slice error that triggers a panic when a crafted input is processed into a short destination buffer. This panic immediately terminates the calling goroutine and can bring down the entire application or service that relies on the library. Because the flaw does not enable arbitrary code execution or persistent data tampering, the primary damage is availability loss to users who depend on the affected functionality.
Affected Systems
Any software that imports golang.org/x/text and calls the Nickname profile function is at risk. The fix is available in updated releases of golang.org/x/text, yet the version range for vulnerability is not explicitly stated, so deployments using the current unpatched implementation should be considered vulnerable until a patched version is installed.
Risk and Exploitability
While no CVSS or EPSS score is provided, the presence of a panic exception indicates a moderate risk level. The likely attack vector is any component that receives external or internal data and feeds it to the Nickname profile; both remote and local inputs that reach the function can trigger the condition. Exploitation requires the attacker to supply the crafted input, but no additional privileges or operating system features are needed, making the vulnerability relatively easy to trigger in many contexts.
OpenCVE Enrichment