CVE-2020-28851

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.14 % (50th)
0.14% Progress
Affected Products 1
Advisories 8

In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

Weaknesses
CWE-129
Improper Validation of Array Index
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2021-01-02 06:15:12
(3 years ago)
Updated Date
2021-02-22 19:14:31
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Golang Go 1.15.4 cpe:2.3:a:golang:go:1.15.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...