← Back to browse · API

CVE-2020-29509

Severity
CRITICAL
CVSS
9.8
EPSS
0.02073
Risk score
39.93
CISA KEV
No
PoC
No
Published
2020-12-14
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2022-1254, GHSA-XHQQ-X44F-9FGG
Products
ecies:Go All versions
Sources
euvd EUVD-2022-1254

Description

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

References