Review
golang.org/x/text
CVE published 2026-10-07
CVE-2026-56851
A panic can occur when parsing crafted input in the Nickname profile of the x/text/secure/precis package in golang.org/x/text. This issue arises when transforming crafted input into a short destination buffer, resulting in an out-of-bounds slice error. The panic is triggered by insufficient input validation, allowing an attacker to craft input that causes the program to panic. Defenders should be aware of [truncated]