Vulnerability Details CVE-2020-28852
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-28852
-
cpe:2.3:a:golang:text:0.1.0
-
cpe:2.3:a:golang:text:0.2.0
-
cpe:2.3:a:golang:text:0.3.0
-
cpe:2.3:a:golang:text:0.3.1
-
cpe:2.3:a:golang:text:0.3.2
-
cpe:2.3:a:golang:text:0.3.3
-
cpe:2.3:a:golang:text:0.3.4