Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

GO-2026-5024 · CVE-2026-39824

Published · Modified

Description

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

Ready to move

Start Securing

Free, no credit card | First findings in minutes