Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Stack exhaustion in all Parse functions in go/parser

GO-2024-3105 · BIT-golang-2024-34155 · CVE-2024-34155

Published · Modified

Description

Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.

Ready to move

Start Securing

Free, no credit card | First findings in minutes