VDB

CVE-2026-56852

CVE-2026-56852 PUBLISHED CVSS 7.5 HIGH

Reported by Go · Published July 21, 2026

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
golang.org/x/textgolang.org/x/text/unicode/norm0
wolfietcd-3.6*, *, *
chainguardgitlab-workhorse-ce-fips-18.8*, *, *
wolfitekton-pipelines-1.7*, *
chainguardtrust-manager-fips*, *
chainguardcert-manager-fips-1.20*, *, *
chainguardk60, 0, 0
chainguardlocal-path-provisioner-fips*, *, *
chainguardrancher-webhook-0.40, 0, 0
chainguardhydra-fips0, 0, 0
chainguardpodman-fips-5.8*, *, *
chainguardlonghorn-share-manager-1.9*, *, *
wolfihelm-push*, *, *
chainguardprometheus-stackdriver-exporter*, *, *
chainguardknative-net-istio-1.20*, *, *
wolfihugo-extended0, 0, 0
wolfiglow0, 0, 0
chainguardgrafana-mimir-3.10, 0, 0
chainguardaws-ebs-csi-driver-fips-1.62*, *, *
chainguardscanner-test-golang-vulnerability-unfixed*, *, *

…and 3023 more

Timeline

  • Jul 17, 2026 CVE Published
  • Jul 21, 2026 Coalition ESS Score
  • Aug 4, 2026 EPSS Score
  • Aug 5, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›