Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.
This is CVE-2024-34155 and Go issue https://go.dev/issue/69138.
This is a PRIVATE issue for CVE-2024-34155, tracked in http://b/362588373 and fixed by https://go-internal-review.git.corp.google.com/c/go/+/1520.
/cc @golang/security and @golang/release
Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.
This is CVE-2024-34155 and Go issue https://go.dev/issue/69138.
This is a PRIVATE issue for CVE-2024-34155, tracked in http://b/362588373 and fixed by https://go-internal-review.git.corp.google.com/c/go/+/1520.
/cc @golang/security and @golang/release