CVE-2026-56852: Infinite loop on invalid input in golang.org/x/text

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploit Status
Not Exploited
Patch Tuesday
2026-Jul
Released
2026-07-25
Last Updated
2026-09-09
EPSS Score
0.47% (percentile: 39.6%)

Detection & Weaponization (1 sources)

Maturity: Exploit

  • GitHub PoC: 1 repositories

Affected Products (42)

Other

  • 21604-17084
  • 21505-17084
  • 21507-17084
  • 21483-17084
  • 21429-17084
  • 21494-17084
  • 21609-17084
  • 21418-17084
  • 21482-17084
  • 21424-17084
  • 21603-17084
  • 21426-17084
  • 21506-17084
  • 21427-17084
  • 21585-17084
  • 21605-17084
  • 21606-17084
  • 21534-17084
  • 21607-17084
  • 21535-17084
  • 21428-17084
  • 21608-17084
  • 21555-17084
  • 21430-17084
  • 21489-17084
  • 21553-17084
  • 21486-17084
  • 21554-17084
  • 21610-17084
  • 21378-17084
  • 21420-17084
  • 21611-17084
  • 21435-17084
  • 21508-17084
  • 21536-17084
  • 21612-17084
  • 21613-17084
  • 21614-17084
  • 21615-17084
  • 21414-17084
  • 21481-17084
  • 21432-17084

Revision History

  • 2026-07-25: Information published.
  • 2026-08-07: Information published.
  • 2026-09-03: Information published.
  • 2026-09-07: Information published.
  • 2026-09-09: Information published.