Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25694
HistoryJun 17, 2020 - 3:55 a.m.

Denial Of Service (DoS)

2020-06-1703:55:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

45.8%

github.com/golang/text is vulnerable to denial of service (DoS). The attack is possible because it does not properly handle the single-byte UTF-16 inputs passing to a UTF-16 decoder, causing an infinite loop if the return value from transformer is ErrShortSrc with atEOF true.