CVE-2026-56851

NameCVE-2026-56851
DescriptionThe Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-golang-x-text (PTS)bookworm0.7.0-1vulnerable
trixie0.22.0-1vulnerable
forky, sid0.41.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-golang-x-textsource(unstable)0.41.0-1

Notes

https://github.com/golang/go/issues/80112
Fixed by: https://github.com/golang/text/commit/02aa981a75cb366b39e71729b935c15a7b4e146a (v0.41.0)

Search for package or bug name: Reporting problems