VDB
CVE-2026-56852
CVE-2026-56852
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published July 21, 2026
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| golang.org/x/text | golang.org/x/text/unicode/norm | 0 |
| wolfi | etcd-3.6 | *, *, * |
| chainguard | gitlab-workhorse-ce-fips-18.8 | *, *, * |
| wolfi | tekton-pipelines-1.7 | *, * |
| chainguard | trust-manager-fips | *, * |
| chainguard | cert-manager-fips-1.20 | *, *, * |
| chainguard | k6 | 0, 0, 0 |
| chainguard | local-path-provisioner-fips | *, *, * |
| chainguard | rancher-webhook-0.4 | 0, 0, 0 |
| chainguard | hydra-fips | 0, 0, 0 |
| chainguard | podman-fips-5.8 | *, *, * |
| chainguard | longhorn-share-manager-1.9 | *, *, * |
| wolfi | helm-push | *, *, * |
| chainguard | prometheus-stackdriver-exporter | *, *, * |
| chainguard | knative-net-istio-1.20 | *, *, * |
| wolfi | hugo-extended | 0, 0, 0 |
| wolfi | glow | 0, 0, 0 |
| chainguard | grafana-mimir-3.1 | 0, 0, 0 |
| chainguard | aws-ebs-csi-driver-fips-1.62 | *, *, * |
| chainguard | scanner-test-golang-vulnerability-unfixed | *, *, * |
…and 3023 more
Timeline
- Jul 17, 2026 CVE Published
- Jul 21, 2026 Coalition ESS Score
- Aug 4, 2026 EPSS Score
- Aug 5, 2026 Security Advisory