---
id: CVE-2026-56851
title: >-
  The Nickname profile can panic with an out-of-bounds slice error when
  transforming crafted input into a short destination buffer.
summary: >-
  The Nickname profile can panic with an out-of-bounds slice error when
  transforming crafted input into a short destination buffer.
severity: none
cwe:
  - CWE-787
vendor: golang.org/x/text
product: golang.org/x/text/secure/precis
affected:
  - golang.org/x/text/secure/precis < 0.41.0
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:20.903'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56851'
references:
  - url: 'https://go.dev/cl/793360'
    label: security@golang.org
  - url: 'https://go.dev/issue/80112'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-6629'
    label: security@golang.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T18:42:20.892Z'
---

## Overview

The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
