CVE-2026-56851: Golang.org/x/text Golang.org/x/text/secure/precis
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
Affected products
- Golang.org/x/text Golang.org/x/text/secure/precis: before 0.41.0 (fixed in 0.41.0)
Published 2026-10-07. Last modified 2026-10-08.