Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-38561


golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.


Published

2022-12-26T06:15:10.560

Last Modified

2025-04-14T17:15:24.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-125
  • Type: Secondary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application golang text < 0.3.7 Yes

References