{"schema_version":"1.9.0","id":"GHSA-5rcv-m4m3-hfh7","published":"2021-05-18T18:34:35Z","modified":"2026-09-10T03:49:04.603920760Z","aliases":["CVE-2020-14040","GO-2020-0015"],"summary":"golang.org/x/text Infinite loop","details":"Go version v0.3.3 of the x/text package fixes a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.\n\n### Specific Go Packages Affected\ngolang.org/x/text/encoding/unicode\ngolang.org/x/text/transform","affected":[{"package":{"name":"golang.org/x/text","ecosystem":"Go","purl":"pkg:golang/golang.org/x/text"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-5rcv-m4m3-hfh7/GHSA-5rcv-m4m3-hfh7.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-14040"},{"type":"WEB","url":"https://github.com/golang/go/issues/39491"},{"type":"WEB","url":"https://github.com/golang/text/commit/23ae387dee1f90d29a23c0e87ee0b46038fbed0e"},{"type":"WEB","url":"https://go-review.googlesource.com/c/text/+/238238"},{"type":"WEB","url":"https://go.dev/cl/238238"},{"type":"WEB","url":"https://go.dev/issue/39491"},{"type":"WEB","url":"https://go.googlesource.com/text/+/23ae387dee1f90d29a23c0e87ee0b46038fbed0e"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/bXVeAmGOqz0"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O"}],"database_specific":{"cwe_ids":["CWE-400","CWE-835"],"github_reviewed":true,"github_reviewed_at":"2021-05-12T14:54:58Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C"}]}