{"id":"GHSA-hfvc-g252-rp4g","summary":"Denial of Service in i18n","details":"This affects the package i18n before version 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.","aliases":["CVE-2020-7791","SNYK-DOTNET-I18N-1050179"],"modified":"2026-07-08T06:49:42.441586195Z","published":"2020-12-14T19:50:22Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-12-14T19:48:58Z","nvd_published_at":"2020-12-11T17:15:00Z","cwe_ids":["CWE-20","CWE-400"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7791"},{"type":"WEB","url":"https://github.com/turquoiseowl/i18n/issues/387"},{"type":"WEB","url":"https://github.com/turquoiseowl/i18n/commit/c418e3345313dc896c1951d8c46ab0b9b12fcbd3"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1573c58dc283b05f7a40a3f5ff0079b5bbde0492d406ee0fe98d40b6@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r2667286c8ceffaf893b16829b9612d8f7c4ee6b30362c6c1b583e3c2@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r33dc233634aedb04fa77db3eb79ea12d15ca4da89fa46a1c585ecb0b@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r394b1ae54693609a60ea8aab02ff045dc92f593aa3aebff562e69958@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r5e08837e695efd36be73510ce58ec05785dbcea077819d8acc2d990d@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r9744574911e7e4edf5f4eeae92a4ccc83e3723cec937950062bb8775@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ra5047392edf1fecba441c9adc8807ed6c5f7d2cc71f2f3bb89f35371@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc2abba7aa0450198494bbee654fce9b97fad72a4989323e189faede4@%3Cdev.myfaces.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc850d0fce066f9eb9e8553172d9207bad7df4d2059d93abc5c7e85c4@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-DOTNET-I18N-1050179"}],"affected":[{"package":{"name":"i18n","ecosystem":"NuGet","purl":"pkg:nuget/i18n"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.15"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.5-candidate","1.0.6","1.0.7","1.0.8","2.1.0","2.1.1","2.1.10","2.1.10-pre000","2.1.10-pre005","2.1.10-pre006","2.1.10-pre011","2.1.11","2.1.11-pre000","2.1.11-pre001","2.1.11-pre002","2.1.12-pre001","2.1.13","2.1.14","2.1.15-pre000","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/12/GHSA-hfvc-g252-rp4g/GHSA-hfvc-g252-rp4g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}