← Back to browse · API

CVE-2020-29511

Severity
CRITICAL
CVSS
9.8
EPSS
0.01942
Risk score
39.88
CISA KEV
No
PoC
No
Published
2020-12-14
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2020-21878, GHSA-G7V2-7V9M-Q9J4
Products
ecies:Go All versions
Sources
euvd EUVD-2020-21878

Description

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

References