upgraded golang.org/x/text v0.38.0 => v0.39.0
% govulncheck ./...
=== Symbol Results ===
Vulnerability #1: GO-2026-5970
Infinite loop on invalid input in golang.org/x/text
More info: https://pkg.go.dev/vuln/GO-2026-5970
Module: golang.org/x/text
Found in: golang.org/x/text@v0.38.0
Fixed in: golang.org/x/text@v0.39.0
Example traces found:
#1: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.Bytes
#2: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.IsNormalString
#3: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.QuickSpan
#4: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.String
Change-Id: I04fc1a8719ef341c466e3437719f8a76b92a340d
Reviewed-on: https://chromium-review.googlesource.com/c/build/+/8131405
Reviewed-by: Philipp Wollermann <philwo@google.com>
Auto-Submit: Fumitoshi Ukai <ukai@google.com>
Commit-Queue: Fumitoshi Ukai <ukai@google.com>
This repository contains tools developed and owned by the Chrome Build Team.
The steps for getting the code are:
git clone https://chromium.googlesource.com/buildWe use the standard Go module workflow to work on our projects.