Versions of the package github.com/nyaruka/phonenumbers...
Moderate severity
Unreviewed
Published
Sep 27, 2025
to the GitHub Advisory Database
•
Updated Sep 27, 2025
Description
Published by the National Vulnerability Database
Sep 27, 2025
Published to the GitHub Advisory Database
Sep 27, 2025
Last updated
Sep 27, 2025
Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".
References