ThreatCluster

Multiple CVEs Identified in Go Language Parsing Functions

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Three vulnerabilities have been reported in Go language parsing functions, affecting various components. CVE-2024-34155 and CVE-2024-34158 both involve stack exhaustion issues, while CVE-2023-24537 is related to an infinite loop in parsing. These vulnerabilities could impact applications utilizing these Go packages.

Timeline

2023-04-06
CVE-2023-24537 published
2024-09-06
CVE-2024-34155 published
2024-09-06
CVE-2024-34158 published
2026-02-18
Information published about vulnerabilities