Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56852

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

A flaw was found in golang.org/x/text. The norm.Iter component can enter an infinite loop when processing input that contains invalid UTF-8 (Unicode Transformation Format - 8-bit) bytes. A remote attacker could exploit this vulnerability by providing specially crafted input, leading to a Denial of Service (DoS) condition where the affected application becomes unresponsive.

Отчет

Important: This flaw in the golang.org/x/text library can lead to a denial of service. An attacker could provide specially crafted invalid UTF-8 input to an application using the affected norm.Iter functionality, causing it to enter an infinite loop and become unresponsive.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Not affected
AWS Load Balancer Operatoralbo/aws-load-balancer-rhel9-operatorAffected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-rhel8-operatorAffected
Confidential Cluster Operatorconfidential-clusters-beta/attestation-key-register-rhel9Under investigation
Confidential Cluster Operatorconfidential-clusters-beta/compute-pcrs-rhel9Under investigation
Confidential Cluster Operatorconfidential-clusters-beta/confidential-cluster-operator-bundleUnder investigation
Confidential Cluster Operatorconfidential-clusters-beta/confidential-cluster-rhel9-operatorUnder investigation
Confidential Cluster Operatorconfidential-clusters-beta/registration-server-rhel9Under investigation
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2504233golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input

EPSS

Процентиль: 40%
0.00475
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

CVSS3: 7.5
nvd
около 2 месяцев назад

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

CVSS3: 7.5
msrc
12 дней назад

Infinite loop on invalid input in golang.org/x/text

CVSS3: 7.5
debian
около 2 месяцев назад

A norm.Iter can enter an infinite loop when handling input containing ...

suse-cvrf
около 2 месяцев назад

Security update for warewulf4

EPSS

Процентиль: 40%
0.00475
Низкий

7.5 High

CVSS3