The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Aug 22, 2024 | Dec 14, 2020 |
| Debian | — | No solution exists | May 15, 2025 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp10 | — | Upgrade golang-develUpgrade golang-helpUpgrade golang | Jan 10, 2024 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade golang-binUpgrade golangUpgrade golang-src | Mar 24, 2021 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade golang-helpUpgrade golangUpgrade golang-devel | Jan 5, 2021 | Dec 14, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 14, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 14, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub