Out-of-Bounds Slice Error in Nickname Profile Affects Go Programming Language
CVE-2026-56851

Currently unrated

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-56851?

The Nickname profile within the Go programming language is susceptible to a vulnerability where an out-of-bounds slice error can occur. This issue is triggered when crafted input is transformed into a buffer with insufficient size, potentially leading to instability in the application. Developers using this functionality should be aware of the risks associated with improperly sized inputs and ensure that adequate input validation is implemented to mitigate the risk of exploitation.

Affected Version(s)

golang.org/x/text/secure/precis 0 < 0.41.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omkhar Arasaratnam (GitHub: omkhar)
.