Description
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Update
AI Analysis

Impact

The Nickname profile in golang.org/x/text/secure/precis contains an out-of-bounds slice error that triggers a panic when a crafted input is processed into a short destination buffer. This panic immediately terminates the calling goroutine and can bring down the entire application or service that relies on the library. Because the flaw does not enable arbitrary code execution or persistent data tampering, the primary damage is availability loss to users who depend on the affected functionality.

Affected Systems

Any software that imports golang.org/x/text and calls the Nickname profile function is at risk. The fix is available in updated releases of golang.org/x/text, yet the version range for vulnerability is not explicitly stated, so deployments using the current unpatched implementation should be considered vulnerable until a patched version is installed.

Risk and Exploitability

While no CVSS or EPSS score is provided, the presence of a panic exception indicates a moderate risk level. The likely attack vector is any component that receives external or internal data and feeds it to the Nickname profile; both remote and local inputs that reach the function can trigger the condition. Exploitation requires the attacker to supply the crafted input, but no additional privileges or operating system features are needed, making the vulnerability relatively easy to trigger in many contexts.

Generated by OpenCVE AI on October 7, 2026 at 19:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade golang.org/x/text to a release that incorporates the patched Nickname profile implementation.
  • Validate all input before invoking the Nickname profile, ensuring that the destination buffer is large enough for the transformation and that malformed data is rejected or sanitized.
  • Wrap calls to the Nickname profile in a defer recover block so that unexpected panics do not crash the entire service.
  • Check the golang.org/x/text project release notes or security advisories for additional guidance when a patch becomes available.

Generated by OpenCVE AI on October 7, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Wed, 07 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
Title Panic parsing crafted input in x/text/secure/precis in golang.org/x/text
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-07T17:46:35.620Z

Reserved: 2026-06-23T15:10:49.352Z

Link: CVE-2026-56851

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:20.903

Modified: 2026-10-07T18:17:20.903

Link: CVE-2026-56851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:00:12Z

Weaknesses
  • CWE-788

    Access of Memory Location After End of Buffer