Review reviewHigh
CVE-2026-56852
golang.org/x/text golang.org/x/text/unicode/norm
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
- CVSS
- 7.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
The CVSS severity warrants an early asset and exposure review.
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
Confirm exposure before applying a vendor-supported change.
Confirm that golang.org/x/text golang.org/x/text/unicode/norm and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.