CVE-2026-56852
Infinite loop on invalid input in golang.org/x/text
CVSS Score
7.5
EPSS Score
0.4%
EPSS Percentile
37th
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
| Vendor | golang.org/x/text |
| Product | golang.org/x/text/unicode/norm |
| Published | Jul 21, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/text golang.org/x/text/unicode/norm
Be the first to know when new high vulnerabilities affecting golang.org/x/text golang.org/x/text/unicode/norm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/text / golang.org/x/text/unicode/norm
0 < 0.39.0
References
Credits
Viky Choi ("vikychoi" on GitHub)