High severity7.5NVD Advisory· Published Aug 7, 2021· Updated Jun 17, 2026
CVE-2021-29923
CVE-2021-29923
Description
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Go/Godescription
- cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*Range: <21.1.1.1.0
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- go-review.googlesource.com/c/go/+/325829/nvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party Advisory
- github.com/golang/go/issues/30999nvdExploitIssue TrackingThird Party Advisory
- github.com/sickcodes/security/blob/master/advisories/SICK-2021-016.mdnvdExploitThird Party Advisory
- defcon.org/html/defcon-29/dc-29-speakers.htmlnvdThird Party Advisory
- github.com/golang/go/issues/43389nvdIssue TrackingThird Party Advisory
- golang.org/pkg/net/nvdVendor Advisory
- security.gentoo.org/glsa/202208-02nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4CHKSFMHZVOBCZSSVRE3UEYNKARTBMTM/nvd
News mentions
0No linked articles in our index yet.