[GO-2022-1059] Denial of service via crafted Accept-Language header in golang.org/x/text/language

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

An attacker may cause a denial of service by crafting an Accept-Language header
which ParseAcceptLanguage will take significant time to parse.

Package Affected Version
pkg:golang/golang.org/x/text/language >= 0.3.7, < 0.3.8
Package Fixed Version
pkg:golang/golang.org/x/text/language = 0.3.8
Source # ID Name URL
Security Advisory https://github.com/advisories/GHSA-69ch-w2m2-3vjp
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/golang.org/x/text/language golang.org/x/text language = 0.3.8
Affected pkg:golang/golang.org/x/text/language golang.org/x/text language >= 0.3.7 < 0.3.8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...