Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31408 | github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input |
Github GHSA |
GHSA-fmjh-f678-cv3x | github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input |
Fri, 03 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Textit
Textit phonenumbers |
|
| CPEs | cpe:2.3:a:textit:phonenumbers:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Textit
Textit phonenumbers |
Mon, 29 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phonenumbers Project
Phonenumbers Project phonenumbers |
|
| Vendors & Products |
Phonenumbers Project
Phonenumbers Project phonenumbers |
Sat, 27 Sep 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range". | |
| Weaknesses | CWE-1286 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-09-29T13:42:17.769Z
Reserved: 2025-09-25T07:30:18.158Z
Link: CVE-2025-10954
Updated: 2025-09-29T13:41:13.247Z
Status : Analyzed
Published: 2025-09-27T05:15:29.803
Modified: 2025-10-03T18:30:04.820
Link: CVE-2025-10954
No data.
OpenCVE Enrichment
Updated: 2025-09-29T09:29:47Z
EUVD
Github GHSA