CVE-2026-56852
ADVISORY - debianSummary
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
- golang-golang-x-text 0.40.0-1 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142674) [bookworm] - golang-golang-x-text (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8) [bullseye] - golang-golang-x-text (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8) https://github.com/golang/go/issues/80142 Fixed by: https://github.com/golang/text/commit/5ae8e578e495731553eddba11b2d0e86c91a00ce (v0.39.0)
EPSS Scoreโ : 0.00446 (0.368)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in