High severity7.5NVD Advisory· Published Jan 2, 2021· Updated Jun 17, 2026
CVE-2020-28852
CVE-2020-28852
Description
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- Go/x/textdescription
- osv-coords8 versionspkg:rpm/almalinux/podmanpkg:rpm/almalinux/podman-dockerpkg:rpm/almalinux/podman-gvproxypkg:rpm/almalinux/podman-pluginspkg:rpm/almalinux/podman-remotepkg:rpm/almalinux/podman-testspkg:rpm/almalinux/git-lfspkg:apk/chainguard/dex-k8s-authenticator
< 2:4.2.0-3.el9+ 7 more
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2:4.2.0-3.el9
- (no CPE)range: < 2.13.3-3.el8_6
- (no CPE)range: < 1.4.0-r33
Patches
Vulnerability mechanics
References
2- github.com/golang/go/issues/42536nvdExploitIssue TrackingThird Party Advisory
- security.netapp.com/advisory/ntap-20210212-0004/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.