CVE-2026-56851: vulnerability in golang.org/x/text/secure/precis
Panic parsing crafted input in x/text/secure/precis in golang.org/x/text
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
Affected products
golang.org/x/text · golang.org/x/text/secure/precis