Golang text/language Input Validation Bypass Vulnerability

description-logoDescription

In x/text in Go 1.15.4, an \"index out of range\" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

affected-products-logoAffected Applications

Go Programming Language

CVE References

CVE-2020-28851