← Back to browse · API

CVE-2020-29510

Severity
CRITICAL
CVSS
9.8
EPSS
0.02047
Risk score
39.92
CISA KEV
No
PoC
No
Published
2020-12-14
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-21877, GHSA-P6MV-VMPW-J23R
Products
ecies:Go unspecified ≤1.15
Sources
euvd EUVD-2020-21877

Description

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

References