---
id: CVE-2020-14040
title: >-
  golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode
  could lead to crash (CVE-2020-14040)
summary: >-
  A denial of service vulnerability was found in the golang.org/x/text library.
  A library or application must use one of the vulnerable functions, such as
  unicode.Transform, transform.String, or transform.Byte, to be susceptible to
  this vuln…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-835
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4.6
affected:
  - openshift_developer_tools_and_services
  - openshift_service_mesh 1
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage 2
  - ceph_storage 3
  - ceph_storage 4
  - enterprise_linux 7
  - enterprise_linux 8
  - openshift_container_platform 3.11
  - openshift_container_platform 4
  - openshift_virtualization 1
  - openshift_virtualization 2
  - storage 3
  - service_telemetry_framework_1_2_for_rhel 8
  - service_telemetry_framework_1_3_for_rhel 8
  - developer_tools_for_red_hat_enterprise_linux_server_v_7
  - enterprise_linux_7_extras
  - 3scale_amp 2.10
  - openshift_jaeger 1.17
  - openshift_container_platform 4.4
  - openshift_container_platform 4.5
  - openshift_service_mesh 1.1
  - developer_tools_for_red_hat_enterprise_linux_workstation_v_7
  - openshift_jaeger 1.20
  - openshift_service_mesh 1.0
  - openshift_serverless 1.11
  - quay v3
  - openshift_container_storage_4_6_on_rhel_8
  - advanced_cluster_management_for_kubernetes_2_1_for_rhel 8
  - openshift_container_platform 4.6
  - openshift_container_platform 4.7
  - enterprise_linux_appstream_v_8
  - fuse 7.9
  - integration
patched:
  - developer_tools_for_red_hat_enterprise_linux_server_v_7
  - enterprise_linux_7_extras
  - 3scale_amp 2.10
  - openshift_jaeger 1.17
  - openshift_container_platform 3.11
  - openshift_container_platform 4.4
  - openshift_container_platform 4.5
  - openshift_service_mesh 1.1
  - developer_tools_for_red_hat_enterprise_linux_workstation_v_7
  - openshift_jaeger 1.20
  - openshift_service_mesh 1.0
  - openshift_serverless 1.11
  - quay v3
  - openshift_container_storage_4_6_on_rhel_8
  - advanced_cluster_management_for_kubernetes_2_1_for_rhel 8
  - openshift_container_platform 4.6
  - openshift_container_platform 4.7
  - enterprise_linux_appstream_v_8
  - fuse 7.9
  - integration
published: '2020-06-17'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T23:29:49+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-14040.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-14040.json
  - url: 'https://access.redhat.com/security/cve/CVE-2020-14040'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1853652'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2020-14040'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2020-14040'
  - url: 'https://github.com/golang/go/issues/39491'
  - url: 'https://groups.google.com/forum/#!topic/golang-announce/bXVeAmGOqz0'
  - url: 'https://access.redhat.com/errata/RHSA-2020:4214'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5055'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5054'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5056'
  - url: 'https://access.redhat.com/errata/RHSA-2021:1129'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3087'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3727'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3783'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3578'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3780'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3369'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5198'
  - url: 'https://access.redhat.com/errata/RHSA-2020:3372'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5149'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0420'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5606'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5605'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0980'
  - url: 'https://access.redhat.com/errata/RHSA-2021:1369'
  - url: 'https://access.redhat.com/errata/RHSA-2020:4297'
  - url: 'https://access.redhat.com/errata/RHSA-2020:4298'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5633'
  - url: 'https://access.redhat.com/errata/RHSA-2020:5635'
  - url: >-
      https://github.com/golang/text/commit/23ae387dee1f90d29a23c0e87ee0b46038fbed0e
  - url: 'https://go-review.googlesource.com/c/text/+/238238'
  - url: 'https://go.dev/cl/238238'
  - url: 'https://go.dev/issue/39491'
  - url: >-
      https://go.googlesource.com/text/+/23ae387dee1f90d29a23c0e87ee0b46038fbed0e
  - url: 'https://groups.google.com/g/golang-announce/c/bXVeAmGOqz0'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TACQFZDPA7AUR6TRZBCX2RGRFSDYLI7O
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0184
epssPercentile: 0.78044
aliases:
  - GHSA-5rcv-m4m3-hfh7
  - GO-2020-0015
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.756Z'
---

## Overview

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.

## Vendor advisories

- **RHSA-2020:4214** · Red Hat · fixed in: Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7), Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7) · released 2020-10-08 · [advisory](https://access.redhat.com/errata/RHSA-2020:4214)
- **RHSA-2020:5055** · Red Hat · fixed in: Red Hat Enterprise Linux 7 Extras · released 2020-11-10 · [advisory](https://access.redhat.com/errata/RHSA-2020:5055)
- **RHSA-2020:5054** · Red Hat · fixed in: Red Hat Enterprise Linux 7 Extras · released 2020-11-10 · [advisory](https://access.redhat.com/errata/RHSA-2020:5054)
- **RHSA-2020:5056** · Red Hat · fixed in: Red Hat Enterprise Linux 7 Extras · released 2020-11-10 · [advisory](https://access.redhat.com/errata/RHSA-2020:5056)
- **RHSA-2021:1129** · Red Hat · fixed in: Red Hat 3Scale AMP 2.10 · released 2021-04-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:1129)
- **RHSA-2020:3087** · Red Hat · fixed in: Red Hat OpenShift Jaeger 1.17 · released 2020-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2020:3087)
- **RHSA-2020:3727** · Red Hat · fixed in: Red Hat OpenShift Container Platform 3.11 · released 2020-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2020:3727)
- **RHSA-2020:3783** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.4 · released 2020-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2020:3783)
- **RHSA-2020:3578** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.5 · released 2020-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2020:3578)
- **RHSA-2020:3780** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.5 · released 2020-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2020:3780)
- **RHSA-2020:3369** · Red Hat · fixed in: Red Hat OpenShift Service Mesh 1.1, OpenShift Service Mesh 1.1 · released 2020-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2020:3369)
- **Red Hat VEX** · Moderate · affected: OpenShift Developer Tools and Services, OpenShift Service Mesh 1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 2, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, … · no fix planned: OpenShift Developer Tools and Services, OpenShift Service Mesh 1, Red Hat Ceph Storage 2, Red Hat Enterprise Linux 7, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-14040.json)

**golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash** — rated Moderate by Red Hat. Released 2020-06-17, updated 2026-09-16.

Affected:

- OpenShift Developer Tools and Services
- OpenShift Service Mesh 1
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 2
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 1
- Red Hat OpenShift Virtualization 2
- Red Hat Storage 3
- Service Telemetry Framework 1.2 for RHEL 8
- Service Telemetry Framework 1.3 for RHEL 8

Fixed:

- Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux 7 Extras
- Red Hat 3Scale AMP 2.10
- Red Hat OpenShift Jaeger 1.17
- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift Container Platform 4.4
- Red Hat OpenShift Container Platform 4.5
- Red Hat OpenShift Service Mesh 1.1
- Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat OpenShift Jaeger 1.20
- OpenShift Service Mesh 1.0
- OpenShift Service Mesh 1.1
- Openshift Serverless 1.11
- Quay v3
- Red Hat OpenShift Container Storage 4.6 on RHEL-8
- Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
- Red Hat OpenShift Container Platform 4.6
- Red Hat OpenShift Container Platform 4.7
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Fuse 7.9
- Red Hat Integration

No fix planned:

- OpenShift Developer Tools and Services
- OpenShift Service Mesh 1
- Red Hat Ceph Storage 2
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Virtualization 1
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift Container Platform 4
- Red Hat Storage 3
- Service Telemetry Framework 1.2 for RHEL 8
- Service Telemetry Framework 1.3 for RHEL 8
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat OpenShift Virtualization 2

Not affected:

- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift Container Platform 4.5
- Red Hat OpenShift Container Platform 4.6
- Red Hat OpenShift Jaeger 1.20
- Red Hat OpenShift Container Storage 4.6 on RHEL-8
- Red Hat OpenShift Container Platform 4.7
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2020:4214
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2020:5055
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2020:5054

## Package advisory (CVE-2020-14040)

Affected packages:

- `golang.org/x/text < 0.3.3`

Patched in:

- `golang.org/x/text 0.3.3`

Source: https://osv.dev/vulnerability/GHSA-5rcv-m4m3-hfh7
