The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-go | Aug 22, 2024 | Dec 14, 2020 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Dec 14, 2020 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-golanghuawei-euleros-2_0_sp10-upgrade-golang-develhuawei-euleros-2_0_sp10-upgrade-golang-help | Jan 10, 2024 | Dec 14, 2020 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-golanghuawei-euleros-2_0_sp5-upgrade-golang-binhuawei-euleros-2_0_sp5-upgrade-golang-src | Mar 24, 2021 | Dec 14, 2020 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-golanghuawei-euleros-2_0_sp9-upgrade-golang-develhuawei-euleros-2_0_sp9-upgrade-golang-help | Jan 5, 2021 | Dec 14, 2020 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Dec 14, 2020 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Dec 14, 2020 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Dec 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub