Skip to content

CVE-2020-14040: Update golang.org/x/text version to v0.3.7#102

Open
majakubiec wants to merge 1 commit intoapex:masterfrom
majakubiec:update-golang-x-text
Open

CVE-2020-14040: Update golang.org/x/text version to v0.3.7#102
majakubiec wants to merge 1 commit intoapex:masterfrom
majakubiec:update-golang-x-text

Conversation

@majakubiec
Copy link

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant