VYPR
Unrated severityNVD Advisory· Published May 22, 2026

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

CVE-2026-39824

Description

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.