CVE-2026-56852: Infinite loop on invalid input in golang.org/x/text
Overview
- Severity
- High (CVSS 7.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Jul
- Released
- 2026-07-25
- Last Updated
- 2026-09-09
- EPSS Score
- 0.47% (percentile: 39.6%)
Detection & Weaponization (1 sources)
Maturity: Exploit
- GitHub PoC: 1 repositories
Affected Products (42)
Other
- 21604-17084
- 21505-17084
- 21507-17084
- 21483-17084
- 21429-17084
- 21494-17084
- 21609-17084
- 21418-17084
- 21482-17084
- 21424-17084
- 21603-17084
- 21426-17084
- 21506-17084
- 21427-17084
- 21585-17084
- 21605-17084
- 21606-17084
- 21534-17084
- 21607-17084
- 21535-17084
- 21428-17084
- 21608-17084
- 21555-17084
- 21430-17084
- 21489-17084
- 21553-17084
- 21486-17084
- 21554-17084
- 21610-17084
- 21378-17084
- 21420-17084
- 21611-17084
- 21435-17084
- 21508-17084
- 21536-17084
- 21612-17084
- 21613-17084
- 21614-17084
- 21615-17084
- 21414-17084
- 21481-17084
- 21432-17084
Revision History
- 2026-07-25: Information published.
- 2026-08-07: Information published.
- 2026-09-03: Information published.
- 2026-09-07: Information published.
- 2026-09-09: Information published.