CVE-2026-56852: Infinite loop on invalid input in golang.org/x/text
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Jul
- Released
- 2026-07-25
- EPSS Score
- 0.45% (percentile: 36.5%)
Affected Products (46)
Other
- 21604-17084
- 21505-17084
- 21507-17084
- 18315-17084
- 21429-17084
- 21494-17084
- 21609-17084
- 21482-17084
- 21424-17084
- 21603-17084
- 21506-17084
- 21427-17084
- 21605-17084
- 21606-17084
- 21534-17084
- 21607-17084
- 21535-17084
- 21608-17084
- 21430-17084
- 21553-17084
- 21486-17084
- 21554-17084
- 21610-17084
- 21378-17084
- 21420-17084
- 21611-17084
- 17793-17084
- 21435-17084
- 21508-17084
- 21536-17084
- 21612-17084
- 21613-17084
- 21614-17084
- 21615-17084
- 21414-17084
- 21432-17084
Open Source Software
- azl3 golang 1.25.11-3 on Azure Linux 3.0
- azl3 moby-engine 25.0.3-18 on Azure Linux 3.0
- azl3 cert-manager 1.12.15-9 on Azure Linux 3.0
- azl3 coredns 1.11.4-17 on Azure Linux 3.0
- azl3 etcd 3.5.30-2 on Azure Linux 3.0
- azl3 gh 2.62.0-18 on Azure Linux 3.0
- azl3 golang 1.26.4-3 on Azure Linux 3.0
- azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0
- azl3 telegraf 1.31.0-23 on Azure Linux 3.0
- azl3 tensorflow 2.16.1-11 on Azure Linux 3.0
Revision History
- 2026-07-25: Information published.